CVE-2022-39407

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
References
Link Resource
https://www.oracle.com/security-alerts/cpuoct2022.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*

History

20 Oct 2022, 05:26

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References (MISC) https://www.oracle.com/security-alerts/cpuoct2022.html - (MISC) https://www.oracle.com/security-alerts/cpuoct2022.html - Patch, Vendor Advisory
First Time Oracle peoplesoft Enterprise Peopletools
Oracle
CPE cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.60:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:*

18 Oct 2022, 21:18

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-18 21:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-39407

Mitre link : CVE-2022-39407

CVE.ORG link : CVE-2022-39407


JSON object : View

Products Affected

oracle

  • peoplesoft_enterprise_peopletools