PeopleSoft Enterprise PeopleTools Vulnerability
CVE-2024-21255

8.8HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 October 2024

Summary

This vulnerability in the PeopleSoft Enterprise PeopleTools software, specifically within the XMLPublisher component, presents a significant risk to users. It allows attackers with low privileges, who can access the network via HTTP, to exploit the system. Successful exploitation can lead to the complete takeover of the PeopleSoft Enterprise PeopleTools application, jeopardizing the confidentiality, integrity, and availability of sensitive data processed within the system. Supported versions affected by this vulnerability include 8.59, 8.60, and 8.61. Organizations using these versions should prioritize applying patches and mitigating exposure to protect their systems.

Affected Version(s)

PeopleSoft Enterprise PeopleTools 8.59

PeopleSoft Enterprise PeopleTools 8.60

PeopleSoft Enterprise PeopleTools 8.61

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.