Unauthenticated Access Vulnerability in Oracle PeopleSoft Enterprise PeopleTools Navigation Pages
CVE-2022-21458
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 19 April 2022
Summary
A significant vulnerability exists within the PeopleSoft Enterprise PeopleTools, specifically affecting the Navigation Pages component. Unauthenticated attackers with network access via HTTP can exploit this flaw, allowing them to potentially manipulate accessible data. While successful exploitation requires human interaction from a third party, the consequences can be severe. Attackers may gain unauthorized update, insert, or delete capabilities for some data, alongside unauthorized read access to specific subsets of data within the affected PeopleSoft environment. This vulnerability presents a considerable risk to the integrity and confidentiality of the data managed within Oracle's PeopleTools.
Affected Version(s)
PeopleSoft Enterprise PT PeopleTools 8.58
PeopleSoft Enterprise PT PeopleTools 8.59
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved