QID 378427

QID 378427: Oracle PeopleSoft Enterprise PeopleTools Product Multiple Vulnerabilities (CPUAPR2023)

Oracle's PeopleSoft applications are designed to address the most complex business requirements. PeopleSoft PeopleTools provides a comprehensive development toolset that supports the development and runtime of PeopleSoft applications.

Affected Versions:
Oracle PeopleSoft Enterprise PeopleTools 8.58
Oracle PeopleSoft Enterprise PeopleTools 8.59
Oracle PeopleSoft Enterprise PeopleTools 8.60

QID Detection Logic (Authenticated):
The authenticated check looks for the installed version of PeopleTools and the corresponding patch. Note: For CVE-2020-14343 only Oracle PeopleSoft Enterprise PeopleTools 8.58 and 8.59 are impacted For CVE-2022-34169 only Oracle PeopleSoft Enterprise PeopleTools 8.58 and for CVE-2022-45047 only Oracle PeopleSoft Enterprise PeopleTools 8.60 are impacted

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Newer versions are available to download. For more information about this product or to check for new releases, go to the PeopleSoft Enterprise PeopleTools .
    Software Advisories
    Advisory ID Software Component Link
    CPUAPR2023 URL Logo www.oracle.com/security-alerts/cpuapr2023.html#AppendixPS