Executive brief
Oracle PeopleSoft Enterprise PeopleTools is a core enterprise resource planning (ERP) platform used to manage HR, payroll, and financial operations. A vulnerability in the SQR component allows an authenticated network attacker to gain unauthorized access to sensitive data and cause the system to crash or hang, disrupting business operations and potentially exposing employee records and financial information.
Technical details
This is a low-complexity network vulnerability in the SQR (SQL Reporting) component of PeopleSoft Enterprise PeopleTools versions 8.61–8.63 that requires low-privilege authentication. The vulnerability allows an authenticated attacker with network access via HTTP to bypass authorization controls and access critical data, or trigger a denial of service by crashing or hanging the application. The exact attack mechanism is not disclosed, but the CVSS vector indicates no user interaction is required and the attack succeeds regardless of the target system configuration (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/A:H). A patch is expected from Oracle.
Affected products
- Oracle PeopleSoft Enterprise PeopleTools 8.61–8.63
Timeline
- 2026-09-15: disclosed