Executive brief
A vulnerability exists in the Mobile Application Platform subcomponent of Oracle PeopleSoft PeopleTools, which is used to manage enterprise human resources and finance operations. An attacker could trick a user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to unauthorized changes in corporate records or the exposure of private employee information.
Technical details
A vulnerability in the Mobile Application Platform subcomponent of Oracle PeopleSoft Enterprise PeopleTools (versions 8.54 and 8.55) allows an unauthenticated attacker with network access via HTTP to compromise the system. The vulnerability is characterized by a CVSS:3.0 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating that while the attack is launched over the network, it requires interaction from a legitimate user (User Interaction: Required). Successful exploitation can lead to unauthorized 'update, insert or delete' access to some data, as well as unauthorized read access to a subset of accessible data. The 'Scope: Changed' metric suggests that the impact may extend beyond the PeopleTools component itself to other integrated Oracle products. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.54, 8.55
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update January 2017