A Vulnerability in Oracle PeopleSoft PeopleTools Could Allow for Remote Code Execution
A vulnerability has been discovered in the Updates Environment Management component of PeopleSoft Enterprise PeopleTools that could allow an attacker with network access via HTTP to completely takeover the software. PeopleSoft is an integrated enterprise resource planning (ERP) software suite widely used by large organizations for managing core business functions, including HR, payroll, finance, supply chain, and campus operations. Successful exploitation of this vulnerability can result in remote code execution, potentially leading to full system compromise.
A remote code execution vulnerability was discovered in Oracle PeopleSoft PeopleTools, allowing an attacker with network access via HTTP to take control of the software. This vulnerability has been targeted by the ShinyHunters extortion gang in ongoing data theft attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HRead the full article
This is a curated summary. The complete article is available at CIS Advisories.