QID 377909

QID 377909: Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUJAN2023)

Oracle's PeopleSoft applications are designed to address the most complex business requirements. PeopleSoft PeopleTools provides a comprehensive development toolset that supports the development and runtime of PeopleSoft applications.

Affected Versions:
Oracle PeopleSoft Enterprise PeopleTools 8.58
Oracle PeopleSoft Enterprise PeopleTools 8.59
Oracle PeopleSoft Enterprise PeopleTools 8.60

QID Detection Logic (Authenticated):
The authenticated check looks for the installed version of PeopleTools and the corresponding patch. Note: For CVE-2022-42003,CVE-2023-21844 only Oracle PeopleSoft Enterprise PeopleTools 8.59 and 8.60 are impacted For CVE-2022-40149 only Oracle PeopleSoft Enterprise PeopleTools 8.58 and for CVE-2023-21845 only Oracle PeopleSoft Enterprise PeopleTools 8.60 are impacted

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Newer versions are available to download. For more information about this product or to check for new releases, go to the PeopleSoft Enterprise PeopleTools .
    Software Advisories
    Advisory ID Software Component Link
    CPUJAN2023 URL Logo www.oracle.com/security-alerts/cpujan2023.html#AppendixPS