Oracle Peoplesoft Enterprise Peopletools vulnerabilities
363 known vulnerabilities affecting oracle/peoplesoft_enterprise_peopletools.
Total CVEs
363
CISA KEV
2
actively exploited
Public exploits
15
Exploited in wild
7
Severity breakdown
CRITICAL24HIGH90MEDIUM236LOW13
Vulnerabilities
Page 13 of 19
CVE-2022-21359P4MEDIUMCVSS 6.1v8.57v8.58+1 more2022-01-19
CVE-2022-21359 [MEDIUM] CVE-2022-21359: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Opti
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Optimization Framework). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human
nvd
CVE-2021-35568P4MEDIUMCVSS 6.1v8.57v8.58+1 more2021-10-20
CVE-2021-35568 [MEDIUM] CVE-2021-35568: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Rich Text Editor). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human intera
nvd
CVE-2022-21470P4MEDIUMCVSS 6.1v8.58v8.592022-04-19
CVE-2022-21470 [MEDIUM] CVE-2022-21470: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Proc
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Process Scheduler). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction
nvd
CVE-2021-35595P4MEDIUMCVSS 6.1v8.57v8.58+1 more2021-10-20
CVE-2021-35595 [MEDIUM] CVE-2021-35595: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Busi
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human inte
nvd
CVE-2018-2951P4MEDIUMCVSS 6.2v8.55v8.562018-07-18
CVE-2018-2951 [MEDIUM] CVE-2018-2951: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Configuration Manager). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft
nvd
CVE-2022-21458P4MEDIUMCVSS 6.1v8.58v8.592022-04-19
CVE-2022-21458 [MEDIUM] CVE-2022-21458: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navi
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navigation Pages, Portal, Query). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require hum
nvd
CVE-2017-10351P4MEDIUMCVSS 6.2v8.54v8.55+1 more2017-10-19
CVE-2017-10351 [MEDIUM] CWE-200 CVE-2017-10351: Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (s
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Application Server). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to co
nvd
CVE-2022-21456P4MEDIUMCVSS 6.1v8.58v8.592022-04-19
CVE-2022-21456 [MEDIUM] CVE-2022-21456: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navi
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Navigation Pages, Portal, Query). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require hum
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5v8.57v8.58+1 more2019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2017-10394P4MEDIUMCVSS 5.4v8.54v8.55+1 more2017-10-19
CVE-2017-10394 [MEDIUM] CVE-2017-10394: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnera
nvd
CVE-2021-32809P4MEDIUMCVSS 5.4v8.57v8.58+1 more2021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2020-2775P4MEDIUMCVSS 5.3v8.56v8.57+1 more2020-04-15
CVE-2020-2775 [MEDIUM] CVE-2020-2775: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Port
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result
nvd
CVE-2025-53061P4MEDIUMCVSS 5.5≥ 8.60, ≤ 8.622025-10-21
CVE-2025-53061 [MEDIUM] CWE-284 CVE-2025-53061: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.60, 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. While the vulnerability is in
nvd
CVE-2024-21070P4MEDIUMCVSS 5.4v8.59v8.60+1 more2024-04-16
CVE-2024-21070 [MEDIUM] CVE-2024-21070: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Sear
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Search Framework). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human intera
nvd
CVE-2026-34307P4MEDIUMCVSS 5.4v8.61v8.622026-04-21
CVE-2026-34307 [MEDIUM] CWE-284 CVE-2026-34307: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Work
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Workflow). Supported versions that are affected are 8.61-8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from
nvd
CVE-2026-47048P4MEDIUMCVSS 5.4v8.61v8.622026-07-21
CVE-2026-47048 [MEDIUM] CWE-601 CVE-2026-47048: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Secu
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction f
nvd
CVE-2026-47024P4MEDIUMCVSS 5.4v8.622026-07-21
CVE-2026-47024 [MEDIUM] CWE-284 CVE-2026-47024: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Pane
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction fr
nvd
CVE-2026-47051P4MEDIUMCVSS 5.4v8.61v8.622026-07-21
CVE-2026-47051 [MEDIUM] CWE-601 CVE-2026-47051: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Secu
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction f
nvd
CVE-2026-47049P4MEDIUMCVSS 4.9v8.61v8.622026-07-21
CVE-2026-47049 [MEDIUM] CWE-284 CVE-2026-47049: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerab
nvd
CVE-2019-2915P4MEDIUMCVSS 6.1v8.56v8.572019-10-16
CVE-2019-2915 [MEDIUM] CVE-2019-2915: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Flui
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Fluid Core). Supported versions that are affected are 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a p
nvd