Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
Oracle PeopleSoft의 PeopleSoft Enterprise PeopleTools 제품(구성 요소: Updates Environment Management)에 존재하는 취약점입니다. 영향을 받는 지원 버전은 8.61 및 8.62입니다. 쉽게 악용 가능한 이 취약점으로 인해 HTTP를 통한 네트워크 접근 권한이 있는 인증되지 않은 공격자가 PeopleSoft Enterprise PeopleTools를 침해할 수 있습니다. 이 취약점의 공격에 성공하면 PeopleSoft Enterprise PeopleTools를 장악할 수 있습니다. CVSS 3.1 기본 점수 9.8(기밀성, 무결성 및 가용성 영향). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Oracle PeopleSoft의 PeopleSoft Enterprise PeopleTools 제품(구성 요소: Updates Environment Management)에 존재하는 취약점입니다. 영향을 받는 지원 버전은 8.61 및 8.62입니다. 쉽게 악용 가능한 이 취약점으로 인해 HTTP를 통한 네트워크 접근 권한이 있는 인증되지 않은 공격자가 PeopleSoft Enterprise PeopleTools를 침해할 수 있습니다. 이 취약점의 공격에 성공하면 PeopleSoft Enterprise PeopleTools를 장악할 수 있습니다. CVSS 3.1 기본 점수 9.8(기밀성, 무결성 및 가용성 영향). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
영향 제품·버전
제품 Oracle Corporation PeopleSoft Enterprise PeopleTools
영향 버전 Oracle Corporation PeopleSoft Enterprise PeopleTools >= 8.61, >= 8.62, 8.61, 8.62
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
조치 기한: 2026.06.15
해당사항 확인방법
Oracle Corporation PeopleSoft Enterprise PeopleTools의 현재 전체 버전이 공식 영향 범위(Oracle Corporation PeopleSoft Enterprise PeopleTools >= 8.61, >= 8.62, 8.61, 8.62)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 수정 버전은 공급사 공식자료 확인 필요 기준을 충족하는지 확인합니다. 이어서 인증 우회 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.