Back to Labs
Security Advisory

CVE-2022-21543

About

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mgmt). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Rainforest analyst review

Oracle's own advisory describes an easily exploitable, unauthenticated, network-reachable flaw in PeopleSoft Enterprise PeopleTools that results in complete takeover of the product — full confidentiality, integrity, and availability impact. PeopleSoft runs core HR, finance, and campus systems, so "takeover" here means an attacker with no credentials reaching one of the most sensitive data platforms an organization operates and owning it outright.

Enterprise applications like PeopleSoft are high-value, and unauthenticated pre-auth takeover bugs in them attract targeted actors who know exactly what these systems hold: employee PII, payroll, financial records. Oracle characterizing it as "easily exploitable" with network access over HTTP means the barrier is low and the reward is enormous, which is the combination that draws deliberate exploitation once details or a proof-of-concept surface. Affected versions are named as 8.58 and 8.59, giving a clear scoping line for triage.

Our emphasis is exposure and the sensitivity of the crown-jewel data behind it. We'd locate any PeopleTools 8.58 or 8.59 instance, sharply prioritize any with internet-facing HTTP access — PeopleSoft portals are sometimes deliberately exposed to remote staff — and drive the Oracle CPU fix on an emergency schedule for those, while restricting access to trusted networks in the interim. Because the impact is total compromise of regulated personal and financial data, we rank this among the highest in the batch and treat exposed instances as breach-consequential, not merely vulnerable.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2022-21543?

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mgmt). Supported versions that are affected are 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.

How severe is CVE-2022-21543?

CVE-2022-21543 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2022-21543 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2022-21543?

Public advisories list the following as affected: peoplesoft enterprise peopletools. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2022-21543?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email