PeopleSoft Enterprise PeopleTools Vulnerability
CVE-2024-21255
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 15 October 2024
Summary
This vulnerability in the PeopleSoft Enterprise PeopleTools software, specifically within the XMLPublisher component, presents a significant risk to users. It allows attackers with low privileges, who can access the network via HTTP, to exploit the system. Successful exploitation can lead to the complete takeover of the PeopleSoft Enterprise PeopleTools application, jeopardizing the confidentiality, integrity, and availability of sensitive data processed within the system. Supported versions affected by this vulnerability include 8.59, 8.60, and 8.61. Organizations using these versions should prioritize applying patches and mitigating exposure to protect their systems.
Affected Version(s)
PeopleSoft Enterprise PeopleTools 8.59
PeopleSoft Enterprise PeopleTools 8.60
PeopleSoft Enterprise PeopleTools 8.61
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved