Unauthenticated Access Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Navigation Pages
CVE-2022-21458

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

A significant vulnerability exists within the PeopleSoft Enterprise PeopleTools, specifically affecting the Navigation Pages component. Unauthenticated attackers with network access via HTTP can exploit this flaw, allowing them to potentially manipulate accessible data. While successful exploitation requires human interaction from a third party, the consequences can be severe. Attackers may gain unauthorized update, insert, or delete capabilities for some data, alongside unauthorized read access to specific subsets of data within the affected PeopleSoft environment. This vulnerability presents a considerable risk to the integrity and confidentiality of the data managed within Oracle's PeopleTools.

Affected Version(s)

PeopleSoft Enterprise PT PeopleTools 8.58

PeopleSoft Enterprise PT PeopleTools 8.59

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.