First published: Tue Jul 18 2023(Updated: )
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle PeopleSoft Enterprise | =8.59 | |
Oracle PeopleSoft Enterprise | =8.60 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-22047.
This vulnerability affects the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft.
This vulnerability affects the Portal component of Oracle PeopleSoft.
The versions 8.59 and 8.60 of Oracle PeopleSoft are affected by this vulnerability.
The severity level of this vulnerability is high with a severity value of 7.
An unauthenticated attacker with network access via HTTP can easily exploit this vulnerability to compromise PeopleSoft Enterprise PeopleTools.
To fix this vulnerability, you should apply the necessary patches and updates provided by Oracle.
You can find more information about this vulnerability on the Oracle Security Alerts website.