CVE-2024-21202

Executive Summary

Oracle PeopleSoft Enterprise PeopleTools (PIA Core Technology) versions 8.59‑8.61 are vulnerable to an unauthenticated HTTP-based flaw that can be exploited by an attacker with network access. The flaw requires human interaction but can lead to unauthorized read, insert, update or delete of PeopleSoft data, potentially affecting other products due to scope change. CVSS 3.1 score 6.1 (Lateral confidentiality and integrity impact). Not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 6.1 (MEDIUM) - Published: 2024-10-15T20:15:08.310 - Last Modified: 2026-08-21T14:32:12.107

Original Description: Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

"We may encounter many defeats but we must not be defeated."

— Maya Angelou
Source: NVD