CVE-2017-10366

CRITICAL

Oracle PeopleSoft Products <8.57 - RCE

Title source: llm

Description

Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (2)

exploitdb WRITEUP
by Vahagn Vardanyan · textwebappsjava
https://www.exploit-db.com/exploits/43594
nomisec WORKING POC 25 stars
by blazeinfosec · poc
https://github.com/blazeinfosec/CVE-2017-10366_peoplesoft

Scores

CVSS v3 9.8
EPSS 0.6438
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (6)
oracle/peoplesoft_enterprise_peopletools 8.54
oracle/peoplesoft_enterprise_peopletools 8.55
oracle/peoplesoft_enterprise_peopletools 8.56
Oracle Corporation/PeopleSoft Enterprise PT PeopleTools 8.54
Oracle Corporation/PeopleSoft Enterprise PT PeopleTools 8.55
Oracle Corporation/PeopleSoft Enterprise PT PeopleTools 8.56
Published Oct 19, 2017
Tracked Since Feb 18, 2026