Oracle PeopleSoft Enterprise PeopleTools PIA Core Technology Unauthenticated Data Access Vulnerability

Vulnerability

An easily exploitable vulnerability has been identified in the PeopleSoft Enterprise PeopleTools product, specifically within the PIA Core Technology component. This vulnerability affects versions 8.60, 8.61, and 8.62. It allows an unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Exploitation of this vulnerability requires human interaction from a person other than the attacker. While the vulnerability resides in PeopleSoft Enterprise PeopleTools, successful attacks may significantly impact additional products. Exploitation can lead to unauthorized update, insert, or delete access to some of the accessible data in PeopleSoft Enterprise PeopleTools, as well as unauthorized read access to a subset of that data.

Impact

Successful exploitation allows for unauthorized access to read, update, insert, or delete certain data within PeopleSoft Enterprise PeopleTools. However, the impact may extend to additional products, indicating a broader scope of concern.

Added: Jul 15, 2025, 11:24 PM
Updated: Jul 15, 2025, 11:24 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.0
exploitability
6.0
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.