CVE-2022-21458 is an easily exploitable vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.58 and 8.59, specifically impacting Navigation Pages, Portal, and Query components. An unauthenticated attacker with network access via HTTP can compromise the system, though successful attacks require human interaction from a non-attacker. This vulnerability allows for unauthorized read, update, insert, or delete access to a subset of PeopleSoft Enterprise PeopleTools data, with potential significant impact on additional products. With a CVSS 3.1 Base Score of 6.1 (Medium), it carries low confidentiality and integrity impacts. There is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.58CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:* | ||
8.59CPE matchmatch criteria | cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.59:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.