Oracle Peoplesoft Enterprise Peopletools vulnerabilities
363 known vulnerabilities affecting oracle/peoplesoft_enterprise_peopletools.
Total CVEs
363
CISA KEV
2
actively exploited
Public exploits
15
Exploited in wild
7
Severity breakdown
CRITICAL24HIGH90MEDIUM236LOW13
Vulnerabilities
Page 16 of 19
CVE-2024-21097P4MEDIUMCVSS 4.9v8.59v8.60+1 more2024-04-16
CVE-2024-21097 [MEDIUM] CVE-2024-21097: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Secu
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can re
nvd
CVE-2011-2315P4MEDIUMCVSS 5.5v8.49v8.50+1 more2011-10-18
CVE-2011-2315 [MEDIUM] CVE-2011-2315: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49, 8.50, and 8.51 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security.
nvd
CVE-2016-3442P4MEDIUMCVSS 5.4v8.53v8.54+1 more2016-04-21
CVE-2016-3442 [MEDIUM] CVE-2016-3442: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Portal.
nvd
CVE-2016-3417P4MEDIUMCVSS 5.4v8.53v8.54+1 more2016-04-21
CVE-2016-3417 [MEDIUM] CVE-2016-3417: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to PIA Search Functionality.
nvd
CVE-2016-0408P4MEDIUMCVSS 5.4v8.53v8.54+1 more2016-04-21
CVE-2016-0408 [MEDIUM] CVE-2016-0408: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 through 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to the Activity Guide sub-component.
nvd
CVE-2016-0460P4MEDIUMCVSS 5.0v8.552016-01-21
CVE-2016-0460 [MEDIUM] CVE-2016-0460: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.55 allows remote attackers to affect integrity via unknown vectors related to Fluid Homepage and NavBar.
nvd
CVE-2022-39407P4MEDIUMCVSS 5.5v8.58v8.59+1 more2022-10-18
CVE-2022-39407 [MEDIUM] CVE-2022-39407: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Secu
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTo
nvd
CVE-2018-3135P4MEDIUMCVSS 4.7v8.55v8.562018-10-17
CVE-2018-3135 [MEDIUM] CVE-2018-3135: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal). Supported versions that are affected are 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interactio
nvd
CVE-2018-3262P4MEDIUMCVSS 4.7v8.55v8.56+1 more2018-10-17
CVE-2018-3262 [MEDIUM] CVE-2018-3262: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Stylesheet). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human
nvd
CVE-2018-2785P4MEDIUMCVSS 4.7v8.54v8.55+1 more2018-04-19
CVE-2018-2785 [MEDIUM] CVE-2018-2785: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Stylesheet). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human
nvd
CVE-2022-21521P4MEDIUMCVSS 4.9v8.58v8.592022-07-19
CVE-2022-21521 [MEDIUM] CVE-2022-21521: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XML Publisher). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can resu
nvd
CVE-2023-21981P4MEDIUMCVSS 4.9v8.58v8.59+1 more2023-04-18
CVE-2023-21981 [MEDIUM] CVE-2023-21981: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elas
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search). Supported versions that are affected are 8.58, 8.59 and 8.60. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability
nvd
CVE-2020-9488P4LOWCVSS 3.7v8.56v8.57+1 more2020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2013-2409P4MEDIUMCVSS 5.0v8.51v8.52+1 more2013-04-17
CVE-2013-2409 [MEDIUM] CVE-2013-2409: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect confidentiality via vectors related to PIA Core Technology.
nvd
CVE-2017-10382P4MEDIUMCVSS 4.7v8.54v8.55+1 more2017-10-19
CVE-2017-10382 [MEDIUM] CVE-2017-10382: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks req
nvd
CVE-2019-2490P4MEDIUMCVSS 4.7v8.55v8.56+1 more2019-01-16
CVE-2019-2490 [MEDIUM] CVE-2019-2490: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Panel Processor). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require h
nvd
CVE-2018-3129P4MEDIUMCVSS 4.3v8.55v8.56+1 more2018-10-17
CVE-2018-3129 [MEDIUM] CVE-2018-3129: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal). Supported versions that are affected are 8.55, 8.56 and 8.57. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human inte
nvd
CVE-2018-2809P4MEDIUMCVSS 4.3v8.54v8.55+1 more2018-04-19
CVE-2018-2809 [MEDIUM] CVE-2018-2809: Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subc
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Homepage & Navigation). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attac
nvd
CVE-2016-0463P4MEDIUMCVSS 4.3v8.53v8.54+1 more2016-01-21
CVE-2016-0463 [MEDIUM] CVE-2016-0463: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote attackers to affect confidentiality via unknown vectors related to Portal.
nvd
CVE-2025-61750P4MEDIUMCVSS 4.3v8.61v8.622025-10-21
CVE-2025-61750 [MEDIUM] CWE-200 CVE-2025-61750: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Quer
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can resu
nvd