Executive brief
A high-severity vulnerability has been identified in Oracle PeopleSoft Enterprise PT PeopleTools, specifically within the WebLogic component. This software is used by organizations to manage large-scale business applications and human resources data. If exploited, an attacker could gain unauthorized access to view, modify, or delete sensitive corporate data, potentially impacting other integrated business systems.
Technical details
This vulnerability (CWE-284) exists in the WebLogic component of Oracle PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62. It is an improper access control flaw that can be exploited by an unauthenticated attacker via HTTP over the network. While the attack complexity is rated as high, a successful exploit results in a scope change (S:C), meaning the impact can extend beyond the PeopleTools environment to other integrated products. Attackers can achieve full confidentiality and integrity compromise, allowing for the unauthorized creation, deletion, or modification of all accessible data. No availability impact was reported. Users should refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle PeopleSoft Enterprise PT PeopleTools 8.61, 8.62
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory