Junglewise Threat Intelligence

CVE-2017-3298: Oracle PeopleSoft Enterprise PeopleTools data manipulation in PIA Core Technology

CVE-2017-3298 · Severity: medium · CVSS 6.1 · Published 2017-01-27

Technologies: Oracle Peoplesoft Enterprise Peopletools. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle PeopleSoft's core technology component, which is used for managing enterprise business applications. An unauthenticated attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to unauthorized changes in corporate records or the exposure of private information.

Technical details

The vulnerability exists within the PIA Core Technology subcomponent of Oracle PeopleSoft Enterprise PeopleTools versions 8.54 and 8.55. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the system. The exploit requires user interaction (UI:R) from a person other than the attacker. Successful exploitation can lead to unauthorized read, update, insert, or delete access to a subset of PeopleTools data. Notably, the vulnerability has a 'Scope' impact (S:C), meaning an attack on PeopleTools may significantly impact additional integrated products.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.54, 8.55

Timeline

  • 2017-01-27: disclosed: Initial publication of the CVE record.
  • 2017-01-27: advisory: Oracle released a security advisory as part of the January 2017 Critical Patch Update.

References

Related threats