Oracle Peoplesoft Enterprise Peopletools vulnerabilities

350 known vulnerabilities affecting oracle/peoplesoft_enterprise_peopletools.

Total CVEs
350
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH86MEDIUM228LOW13

Vulnerabilities

Page 17 of 18
CVE-2016-0683MEDIUMCVSS 5.4v8.53v8.54+1 more2016-04-21
CVE-2016-0683 [MEDIUM] CVE-2016-0683: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Search Framework.
nvd
CVE-2015-3197MEDIUMCVSS 5.9v8.53v8.54+1 more2016-02-15
CVE-2015-3197 [MEDIUM] CWE-200 CVE-2015-3197: ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disable ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by performing computations on SSLv2 traffic, related to the get_client_master_key and get_client_hello functions.
nvd
CVE-2016-0471MEDIUMCVSS 4.3v8.53v8.542016-01-21
CVE-2016-0471 [MEDIUM] CVE-2016-0471: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote attackers to affect confidentiality via unknown vectors related to Multichannel Framework.
nvd
CVE-2016-0462MEDIUMCVSS 4.0v8.53v8.542016-01-21
CVE-2016-0462 [MEDIUM] CVE-2016-0462: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect confidentiality via unknown vectors related to Multichannel Framework, a different vulnerability than CVE-2015-2650.
nvd
CVE-2016-0587MEDIUMCVSS 4.0v8.53v8.54+1 more2016-01-21
CVE-2016-0587 [MEDIUM] CVE-2016-0587: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality via unknown vectors related to File Processing.
nvd
CVE-2016-0460MEDIUMCVSS 5.0v8.552016-01-21
CVE-2016-0460 [MEDIUM] CVE-2016-0460: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.55 allows remote attackers to affect integrity via unknown vectors related to Fluid Homepage and NavBar.
nvd
CVE-2016-0463MEDIUMCVSS 4.3v8.53v8.54+1 more2016-01-21
CVE-2016-0463 [MEDIUM] CVE-2016-0463: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote attackers to affect confidentiality via unknown vectors related to Portal.
nvd
CVE-2016-0474LOWCVSS 3.5v8.54v8.552016-01-21
CVE-2016-0474 [LOW] CVE-2016-0474: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.
nvd
CVE-2016-0473LOWCVSS 3.5v8.54v8.552016-01-21
CVE-2016-0473 [LOW] CVE-2016-0473: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect integrity via unknown vectors related to Fluid Core.
nvd
CVE-2015-7940MEDIUMCVSS 5.0v8.54v8.552015-11-09
CVE-2015-7940 [MEDIUM] CWE-200 CVE-2015-7940: The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack."
nvd
CVE-2013-3759MEDIUMCVSS 4.3v8.52v8.532013-07-17
CVE-2013-3759 [MEDIUM] CVE-2013-3759: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote attackers to affect integrity via vectors related to PIA Search Functionality.
nvd
CVE-2013-3761MEDIUMCVSS 4.3v8.522013-07-17
CVE-2013-3761 [MEDIUM] CVE-2013-3761: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products Portal 9.1 and PeopleTools 8.52 allows remote attackers to affect integrity via vectors related to PIA Core Technology.
nvd
CVE-2013-2409MEDIUMCVSS 5.0v8.51v8.52+1 more2013-04-17
CVE-2013-2409 [MEDIUM] CVE-2013-2409: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect confidentiality via vectors related to PIA Core Technology.
nvd
CVE-2013-2406LOWCVSS 3.5v8.51v8.52+1 more2013-04-17
CVE-2013-2406 [LOW] CVE-2013-2406: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology.
nvd
CVE-2011-2315MEDIUMCVSS 5.5v8.49v8.50+1 more2011-10-18
CVE-2011-2315 [MEDIUM] CVE-2011-2315: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49, 8.50, and 8.51 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security.
nvd
CVE-2011-3520LOWCVSS 2.8v8.49v8.50+1 more2011-10-18
CVE-2011-3520 [LOW] CVE-2011-3520: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49, 8.50, and 8.51 allows remote authenticated users to affect integrity via unknown vectors related to Personalization.
nvd
CVE-2011-2280MEDIUMCVSS 4.0v8.49.31v8.50.20+1 more2011-07-21
CVE-2011-2280 [MEDIUM] CVE-2011-2280: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-2274.
nvd
CVE-2011-2275MEDIUMCVSS 4.3v8.49.32v8.50.21+1 more2011-07-21
CVE-2011-2275 [MEDIUM] CVE-2011-2275: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2011-2274LOWCVSS 3.5v8.49.31v8.49.32+3 more2011-07-21
CVE-2011-2274 [LOW] CVE-2011-2274: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-2280.
nvd
CVE-2011-2282LOWCVSS 3.5v8.50.21v8.51.112011-07-21
CVE-2011-2282 [LOW] CVE-2011-2282: Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Pr Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.50.20 and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors.
nvd