
CVE-2026-35273
Una vulnerabilità che colpisce Oracle PeopleSoft Enterprise PeopleTools che consente a aggressori remoti di compromettere i sistemi vulnerabili senza autenticazione.
CVE-2026-35273 è una vulnerabilità critica che colpisce il componente Updates Environment Management di Oracle PeopleSoft Enterprise PeopleTools.
La vulnerabilità può essere sfruttata da remoto attraverso la rete senza autenticazione, con il potenziale risultato di:
| Proprietà | Valore |
|---|---|
| CVE | CVE-2026-35273 |
| Vendor | Oracle |
| Prodotto | PeopleSoft Enterprise PeopleTools |
| Gravità | Critica |
| CVSS v3.1 | 9.8 |
| CWE | CWE-306 |
| Vettore di attacco | Rete |
| Autenticazione | Non richiesta |
| Interazione utente | Nessuna |
| Impatto | Esecuzione Remota di Codice |
| Prodotto | Versione |
|---|---|
| Oracle PeopleTools | 8.61 |
| Oracle PeopleTools | 8.62 |
Attack Vector : Network
Attack Complexity : Low
Privileges Required: None
User Interaction : None
Scope : Unchanged
Confidentiality : High
Integrity : High
Availability : High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lo sfruttamento riuscito può consentire agli aggressori di:

I team di sicurezza dovrebbero monitorare per:
Unexpected requests targeting:
- Environment Management endpoints
- Update services
- Administrative interfaces
cmd.exe
powershell.exe
bash
sh
python
perl
.jsp
.php
.asp
.aspx
.war
.jar
Unexpected outbound connections
Reverse shell behavior
Beaconing activity
Aggiornare PeopleTools alla versione corretta di Oracle.
✓ Limit access to management interfaces
✓ Restrict trusted administrator IPs
✓ Use VPN access where possible
✓ Web server logs
✓ Process creation logs
✓ Authentication logs
✓ Network telemetry
Cercare:
New administrator accounts
Unknown scheduled tasks
Suspicious web files
Unusual outbound traffic
| Categoria | Dettagli |
|---|---|
| Tipo di Vulnerabilità | Autenticazione Mancante |
| CWE | CWE-306 |
| Esposizione | Remota |
| Sfruttabilità | Alta |
| Autenticazione Richiesta | No |
| Privilegi Richiesti | No |
| Interazione Utente | No |
Questo repository è fornito per:
Non è inteso per facilitare l'accesso non autorizzato o lo sfruttamento dei sistemi.
Oracle PeopleSoft PeopleTools — CVE-2026-35273