cbcvebase.

Oracle Peoplesoft Enterprise Peopletools vulnerabilities

363 known vulnerabilities affecting oracle/peoplesoft_enterprise_peopletools.

Total CVEs
363
CISA KEV
2
actively exploited
Public exploits
15
Exploited in wild
7
Severity breakdown
CRITICAL24HIGH90MEDIUM236LOW13

Vulnerabilities

Page 11 of 19
CVE-2022-21520P4MEDIUMCVSS 6.1v8.58v8.592022-07-19
CVE-2022-21520 [MEDIUM] CVE-2022-21520: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Flui Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a
nvd
CVE-2024-21065P4MEDIUMCVSS 6.1v8.59v8.60+1 more2024-04-16
CVE-2024-21065 [MEDIUM] CWE-601 CVE-2024-21065: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Work Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human intera
nvd
CVE-2023-22080P4MEDIUMCVSS 6.1v8.59v8.602023-10-17
CVE-2023-22080 [MEDIUM] CVE-2023-22080: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interactio
nvd
CVE-2024-21178P4MEDIUMCVSS 6.1v8.59v8.60+1 more2024-07-16
CVE-2024-21178 [MEDIUM] CWE-79 CVE-2024-21178: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Port Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interacti
nvd
CVE-2025-30748P4MEDIUMCVSS 6.1v8.60v8.61+1 more2025-07-15
CVE-2025-30748 [MEDIUM] CWE-863 CVE-2025-30748: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require hu
nvd
CVE-2017-10045P4MEDIUMCVSS 5.3v8.54v8.552017-08-08
CVE-2017-10045 [MEDIUM] CVE-2017-10045: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require
nvd
CVE-2018-2653P4MEDIUMCVSS 5.3v8.54v8.55+1 more2018-01-18
CVE-2018-2653 [MEDIUM] CVE-2018-2653: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Connected Query). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this v
nvd
CVE-2018-3016P4MEDIUMCVSS 5.4v8.55v8.562018-07-18
CVE-2018-3016 [MEDIUM] CVE-2018-3016: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulne
nvd
CVE-2020-14806P4MEDIUMCVSS 5.3v8.56v8.57+1 more2020-10-21
CVE-2020-14806 [MEDIUM] CVE-2020-14806: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Quer Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can resul
nvd
CVE-2020-14558P4MEDIUMCVSS 5.3v8.56v8.57+1 more2020-07-15
CVE-2020-14558 [MEDIUM] CVE-2020-14558: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Port Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can resu
nvd
CVE-2021-2407P4MEDIUMCVSS 5.3v8.57v8.58+1 more2021-07-21
CVE-2021-2407 [MEDIUM] CVE-2021-2407: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Port Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result
nvd
CVE-2023-21845P4MEDIUMCVSS 5.4v8.602023-01-18
CVE-2023-21845 [MEDIUM] CVE-2023-21845: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Pane Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in
nvd
CVE-2023-21916P4MEDIUMCVSS 5.3v8.58v8.59+1 more2023-04-18
CVE-2023-21916 [MEDIUM] CVE-2023-21916: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Web Server). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can r
nvd
CVE-2025-53065P4MEDIUMCVSS 5.4v8.60v8.61+1 more2025-10-21
CVE-2025-53065 [MEDIUM] CWE-125 CVE-2025-53065: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require hu
nvd
CVE-2025-53063P4MEDIUMCVSS 5.4v8.60v8.61+1 more2025-10-21
CVE-2025-53063 [MEDIUM] CWE-125 CVE-2025-53063: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require hum
nvd
CVE-2025-53048P4MEDIUMCVSS 5.4≥ 8.60, ≤ 8.622025-10-21
CVE-2025-53048 [MEDIUM] CWE-125 CVE-2025-53048: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human
nvd
CVE-2026-21938P4MEDIUMCVSS 5.4v8.60v8.61+1 more2026-01-20
CVE-2026-21938 [MEDIUM] CVE-2026-21938: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Port Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from
nvd
CVE-2020-9281P4MEDIUMCVSS 6.1v8.56v8.57+1 more2020-03-07
CVE-2020-9281 [MEDIUM] CWE-79 CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 a A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v8.57v8.582019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2015-7940P4MEDIUMCVSS 5.0v8.54v8.552015-11-09
CVE-2015-7940 [MEDIUM] CWE-200 CVE-2015-7940: The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
nvd
Oracle Peoplesoft Enterprise Peopletools vulnerabilities | cvebase