Vulnerability in PeopleSoft Enterprise PeopleTools by Oracle
CVE-2023-22080

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

This vulnerability in Oracle's PeopleSoft Enterprise PeopleTools component, specifically affecting versions 8.59 and 8.60, allows unauthenticated attackers to compromise the system via HTTP. Exploitation requires human interaction from a third-party user, potentially leading to unauthorized data modifications such as updates, inserts, or deletions, as well as read access to sensitive information within PeopleSoft. The implications may extend beyond the core product, affecting various interlinked systems and increasing the overall risk to organizational data security.

Affected Version(s)

PeopleSoft Enterprise PT PeopleTools 8.59

PeopleSoft Enterprise PT PeopleTools 8.60

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.