Oracle PeopleSoft Enterprise PeopleTools
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:*:*:*:*:*:*:*
- 8.60
- 8.61
- 8.62
A vulnerability exists in the PeopleSoft Enterprise PeopleTools product, specifically within the PIA Core Technology component. Affected versions include 8.60, 8.61, and 8.62. This vulnerability allows a low-privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Exploitation requires human interaction from a third party. While the vulnerability is contained within PeopleSoft Enterprise PeopleTools, successful attacks could significantly impact other products, leading to a scope change. Exploitation of this vulnerability could result in unauthorized read access to certain subsets of PeopleSoft Enterprise PeopleTools data, as well as unauthorized update, insert, or delete access to other accessible data within the same environment.
Exploitation allows for unauthorized read access to some PeopleSoft Enterprise PeopleTools data, as well as unauthorized modification of accessible data, including updates, inserts, or deletions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.