Junglewise Threat Intelligence

CVE-2017-3300: Oracle PeopleSoft PeopleTools XSS in Multichannel Framework

CVE-2017-3300 · Severity: medium · CVSS 6.1 · Published 2017-01-27

Technologies: Oracle Peoplesoft Enterprise Peopletools. Vendors: Oracle.

Executive brief

A vulnerability exists in the Multichannel Framework subcomponent of Oracle PeopleSoft Enterprise PeopleTools, a platform used for managing enterprise business applications. An attacker can exploit this flaw to gain unauthorized access to view, modify, or delete certain business data. Successful exploitation requires a legitimate user to interact with a malicious link or page, which could lead to broader impacts across connected enterprise systems.

Technical details

A cross-site scripting (XSS) vulnerability (CWE-79) exists in the Multichannel Framework subcomponent of Oracle PeopleSoft Enterprise PeopleTools versions 8.54 and 8.55. The flaw is easily exploitable by an unauthenticated attacker via HTTP, though it requires human interaction from a victim (user interaction). Successful exploitation allows the attacker to perform unauthorized updates, inserts, or deletions of accessible data, as well as unauthorized read access to a subset of data. Because the vulnerability has a 'Changed' scope (S:C), an attack on PeopleTools may impact other integrated products. Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle PeopleSoft Enterprise PeopleTools 8.54, 8.55

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update released

References

Related threats