Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
| Vendor | Product | Versions |
|---|---|---|
| oracle | peoplesoft_enterprise_peopletools | 8.61, 8.62 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| oracle | peoplesoft | cert_advisory | 90% |
Updated description with details on exploitation by the ShinyHunters group, added new IoCs, and included new tags related to ransomware and extortion.
Added CWE-918 for server-side request forgery, updated description with new technical details, and included new IoCs and tags.
Updated description with detailed exploitation methods and added a new IOC for the command and control server.
Updated description with detailed exploitation information, noted that patches do not appear to be available, and added new IoCs and tags related to the exploitation.
Updated description with details about the ShinyHunters extortion campaign and added new CWE and tags.
Updated description with details on unauthenticated remote code execution and added new IoCs and a new tag for zero-day.
Updated description with detailed technical information about the exploitation campaign and added new IoCs including five IP addresses and a domain.
Updated description with new details about exploitation in the wild and clarified that no patch is available.
Updated description with details on mitigations and zero-day attacks, and added new IOC and tags related to the ShinyHunters group.
Updated exploit status to actively exploited and added information about potentially affected earlier versions.
Marked exploit as available and actively exploited, and added new tags related to the vulnerability.
Updated description with new technical details and clarified that no exploit is available.
Initial creation