Executive brief
A vulnerability exists in the Integration Broker component of Oracle PeopleSoft PeopleTools, which is used for managing business process flows and data integration. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive business data. Successful exploitation requires a legitimate user to perform a specific action, such as clicking a link, which could lead to a significant breach of confidentiality.
Technical details
The vulnerability is classified as an information disclosure (CWE-200) within the Integration Broker subcomponent of Oracle PeopleSoft Enterprise PeopleTools versions 8.54 and 8.55. It is remotely exploitable via HTTP by an attacker with low-level privileges. The exploit requires user interaction from someone other than the attacker (UI:R), suggesting a cross-site request forgery (CSRF) or similar client-side attack vector. Successful exploitation allows the attacker to read sensitive data or gain complete access to all data accessible via PeopleTools, impacting confidentiality but not integrity or availability. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.54, 8.55
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle January 2017 Critical Patch Update released