Executive brief
Oracle PeopleSoft Enterprise PeopleTools is an application development platform used to build enterprise human resources and financial management systems. A privilege escalation vulnerability in the SQR component allows a highly privileged attacker with local infrastructure access to gain complete control of the system, potentially affecting additional connected enterprise applications that rely on PeopleTools.
Technical details
This is a privilege escalation vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools affecting versions 8.61 through 8.63. The vulnerability is classified as difficult to exploit and requires a high-privileged attacker with local infrastructure access, high complexity attack conditions, and user interaction from a non-attacker. The attack vector is local, not remotely exploitable. Successful exploitation can result in complete compromise of the PeopleTools environment with impacts to confidentiality, integrity, and availability. Additionally, the vulnerability has scope change implications, meaning exploitation may affect other products downstream. Oracle has issued this advisory with no public indication of patch availability at the time of publication.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61-8.63
Timeline
- 2026-09-15: disclosed