PT-2026-3708 · Oracle · Peoplesoft Enterprise Hcm Human Resources

CVE-2026-21961

·

Publicado

2026-01-20

·

Atualizado

2026-01-21

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle PeopleSoft Enterprise HCM Human Resources version 9.2
Description A flaw exists in the PeopleSoft Enterprise HCM Human Resources component, specifically within Company Dir / Org Chart Viewer and Employee Snapshot. This issue allows a network attacker, without needing to authenticate, to compromise the system. Exploitation requires interaction from a user other than the attacker. Successful exploitation could lead to unauthorized data modification, insertion, or deletion, as well as unauthorized read access to data within PeopleSoft Enterprise HCM Human Resources. The attack may also impact additional products.
Recommendations Update PeopleSoft Enterprise HCM Human Resources version 9.2 to a newer, fixed version. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-00991
CVE-2026-21961

Produtos afetados

Peoplesoft Enterprise Hcm Human Resources