CVE-2023-22047
Oracle Peoplesoft - Unauthenticated File Read
Record summary
CVE-2023-22047 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PeopleSoft Enterprise PT PeopleToolsBrowse Oracle Corporation / PeopleSoft Enterprise PT PeopleTools | CVE List | 8.59 | affected |
| 8.60 | affected |
Proofs of concept
1Repository PoCs
GitHubtuo4n8/CVE-2023-22047Repository PoCby tuo4n8Stars: 12Not analyzed4 files
Nuclei templates
1ProjectDiscoveryHIGHOracle Peoplesoft - Unauthenticated File ReadCVSS 7.5
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component- Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data.
Impact
Unauthenticated attackers can read arbitrary files from the PeopleSoft server through the wsrp-url parameter in the Portal component, potentially accessing critical data including configuration files and sensitive employee information.
Remediation
Update Oracle PeopleSoft Enterprise PeopleTools to a version newer than 8.60 that validates and restricts file:// URLs in the wsrp-url parameter.
Source: ProjectDiscovery