CVE-2017-10366
CRITICALOracle PeopleSoft Products <8.57 - RCE
Title source: llmDescription
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Performance Monitor). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Exploits (2)
nomisec
WORKING POC
25 stars
by blazeinfosec · poc
https://github.com/blazeinfosec/CVE-2017-10366_peoplesoft
Scores
CVSS v3
9.8
EPSS
0.6438
EPSS Percentile
98.5%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
Status
published
Products (6)
oracle/peoplesoft_enterprise_peopletools
8.54
oracle/peoplesoft_enterprise_peopletools
8.55
oracle/peoplesoft_enterprise_peopletools
8.56
Oracle Corporation/PeopleSoft Enterprise PT PeopleTools
8.54
Oracle Corporation/PeopleSoft Enterprise PT PeopleTools
8.55
Oracle Corporation/PeopleSoft Enterprise PT PeopleTools
8.56
Published
Oct 19, 2017
Tracked Since
Feb 18, 2026