PT-2026-3701 · Oracle · Peoplesoft Enterprise Peopletools+1

CVE-2026-21951

·

Publicado

2026-01-20

·

Atualizado

2026-01-21

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle PeopleSoft versions 8.60 through 8.62
Description A flaw exists in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools. An unauthenticated attacker with network access via HTTP can compromise the system. Exploitation requires interaction from a user other than the attacker. Successful attacks may lead to unauthorized data modification, insertion, or deletion, as well as unauthorized data access.
Recommendations Update PeopleSoft Enterprise PeopleTools version 8.60 to a later version. Update PeopleSoft Enterprise PeopleTools version 8.61 to a later version. Update PeopleSoft Enterprise PeopleTools version 8.62 to a later version.

Correção

XSS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00994
CVE-2026-21951

Produtos afetados

Peoplesoft
Peoplesoft Enterprise Peopletools