PeopleSoft's vulnerability footprint centers on its enterprise human-resources management and financial system suite, products that occupy critical positions in large organizations' back-office infrastructure despite a narrow product portfolio. The recurring exposure involves its PeopleTools platform and HRMS applications, where observed vulnerability patterns reflect the complexity of business-process and data-integration logic in large enterprise software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Peoplesoft over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0950HIGH PeopleSoft PeopleTools 8.1x, 8.2x, and 8.4x allows remote attackers to execute arbitrary commands by uploading a file to the IClient Servlet, guessing the insufficiently random (sy | Dec 15, 2003 | 7.5 | 24 | NO | NO |
CVE-2003-0104MEDIUM Directory traversal vulnerability in PeopleTools 8.10 through 8.18, 8.40, and 8.41 allows remote attackers to overwrite arbitrary files via the SchedulerTransfer servlet. | Mar 18, 2003 | 5.0 | 20 | NO | NO |
CVE-2003-0627MEDIUM psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to cause a denial of service (application crash), possibly via the headername and footername argumen | Dec 31, 2003 | 5.0 | 19 | NO | NO |
CVE-2004-2435MEDIUM Cross-site scripting (XSS) vulnerability in PeopleSoft Human Resources Management System (HRMS) 7.0, when "web enabled" using HTML Access, allows remote attackers to inject arbitra | Dec 31, 2004 | 4.3 | 18 | NO | NO |
CVE-2003-0628MEDIUM PeopleSoft Gateway Administration servlet (gateway.administration) in PeopleTools 8.43 and earlier allows remote attackers to obtain the full pathnames for server-side include (SSI | Dec 15, 2003 | 5.0 | 15 | NO | NO |
CVE-2003-0626MEDIUM psdoccgi.exe in PeopleSoft PeopleTools 8.4 through 8.43 allows remote attackers to read arbitrary files via the (1) headername or (2) footername arguments. | Nov 13, 2003 | 5.0 | 15 | NO | NO |
CVE-2002-1252MEDIUM The Application Messaging Gateway for PeopleTools 8.1x before 8.19, as used in various PeopleSoft products, allows remote attackers to read arbitrary files via certain XML External | Feb 7, 2003 | 5.0 | 15 | NO | NO |
CVE-2003-0629MEDIUM Cross-site scripting (XSS) vulnerability in PeopleSoft IScript environment for PeopleTools 8.43 and earlier allows remote attackers to insert arbitrary web script via a certain HTT | Dec 15, 2003 | 4.3 | 14 | NO | NO |
The PSCipher function in PeopleSoft People Tools 8.4x uses PKCS #5 with a fixed DES key to store user passwords, which makes it easier for local users to guess passwords using a di | Feb 8, 2006 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Peoplesoft.
Media articles that mention a CVE ID that affects a product developed by Peoplesoft — matched by CVE ID, not by vendor name.