Executive brief
A vulnerability exists in the search functionality of Oracle PeopleSoft Enterprise PeopleTools, a platform used for managing enterprise applications. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to unauthorized changes to records or the exposure of private organizational information.
Technical details
A vulnerability in the PeopleSoft Internet Architecture (PIA) Search Functionality subcomponent of Oracle PeopleSoft Enterprise PeopleTools (versions 8.54 and 8.55) allows an unauthenticated remote attacker to impact the confidentiality and integrity of the system. The exploit is delivered via HTTP and requires interaction from a person other than the attacker (User Interaction: Required). While the vulnerability exists within PeopleTools, the impact can extend to other products (Scope: Changed). Successful exploitation can result in unauthorized read, update, insert, or delete access to a subset of accessible data. The vulnerability is addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.54, 8.55
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published