QID 377645

Date Published: 2022-10-19

QID 377645: Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUOCT2022)

Oracle's PeopleSoft applications are designed to address the most complex business requirements. PeopleSoft PeopleTools provides a comprehensive development toolset that supports the development and runtime of PeopleSoft applications.

Affected Versions:
Oracle PeopleSoft Enterprise PeopleTools 8.58
Oracle PeopleSoft Enterprise PeopleTools 8.59
Oracle PeopleSoft Enterprise PeopleTools 8.60

QID Detection Logic (Authenticated):
The authenticated check looks for the installed version of PeopleTools and the corresponding patch. Note: For CVE-2022-21639 only Oracle PeopleSoft Enterprise PeopleTools 8.59 and 8.60 are impacted

Successful exploitation of this vulnerability allows remotely exploitation without authentication.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Newer versions are available to download. For more information about this product or to check for new releases, go to the Oracle PeopleSoft Products.
    Software Advisories
    Advisory ID Software Component Link
    cpuoct2022 URL Logo www.oracle.com/security-alerts/cpuoct2022.html#AppendixPS