Vulnerability in PeopleSoft Enterprise PeopleTools by Oracle
CVE-2023-22080
6.1MEDIUM
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 17 October 2023
Summary
This vulnerability in Oracle's PeopleSoft Enterprise PeopleTools component, specifically affecting versions 8.59 and 8.60, allows unauthenticated attackers to compromise the system via HTTP. Exploitation requires human interaction from a third-party user, potentially leading to unauthorized data modifications such as updates, inserts, or deletions, as well as read access to sensitive information within PeopleSoft. The implications may extend beyond the core product, affecting various interlinked systems and increasing the overall risk to organizational data security.
Affected Version(s)
PeopleSoft Enterprise PT PeopleTools 8.59
PeopleSoft Enterprise PT PeopleTools 8.60
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved