
CVE-2026-35273
취약한 시스템에 대해 원격 공격자가 인증 없이 손상시킬 수 있는 Oracle PeopleSoft Enterprise PeopleTools의 취약점
CVE-2026-35273은 Oracle PeopleSoft Enterprise PeopleTools의 Updates Environment Management 구성 요소에 영향을 미치는 치명적인 취약점입니다.
이 취약점은 네트워크를 통해 인증 없이 원격으로 악용될 수 있으며, 다음과 같은 결과를 초래할 수 있습니다.
| 제품 | 버전 |
|---|---|
| Oracle PeopleTools | 8.61 |
| Oracle PeopleTools | 8.62 |
Attack Vector : Network
Attack Complexity : Low
Privileges Required: None
User Interaction : None
Scope : Unchanged
Confidentiality : High
Integrity : High
Availability : High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
악용에 성공할 경우 공격자는 다음을 수행할 수 있습니다.
보안 팀은 다음 사항을 모니터링해야 합니다.
Unexpected requests targeting:
- Environment Management endpoints
- Update services
- Administrative interfaces
cmd.exe
powershell.exe
bash
sh
python
perl
.jsp
.php
.asp
.aspx
.war
.jar
Unexpected outbound connections
Reverse shell behavior
Beaconing activity
PeopleTools를 Oracle의 수정된 릴리스로 업데이트합니다.
✓ Limit access to management interfaces
✓ Restrict trusted administrator IPs
✓ Use VPN access where possible
✓ Web server logs
✓ Process creation logs
✓ Authentication logs
✓ Network telemetry
다음을 검색합니다.
New administrator accounts
Unknown scheduled tasks
Suspicious web files
Unusual outbound traffic
이 저장소는 다음을 위해 제공됩니다.
시스템에 대한 무단 액세스 또는 악용을 용이하게 하기 위한 것이 아닙니다.
Oracle PeopleSoft PeopleTools — CVE-2026-35273
| 속성 | 값 |
|---|
| CVE | CVE-2026-35273 |
| 공급업체 | Oracle |
| 제품 | PeopleSoft Enterprise PeopleTools |
| 심각도 | 치명적 |
| CVSS v3.1 | 9.8 |
| CWE | CWE-306 |
| 공격 경로 | 네트워크 |
| 인증 | 필요 없음 |
| 사용자 상호 작용 | 없음 |
| 영향 | 원격 코드 실행 |
| 범주 | 세부 사항 |
|---|
| 취약점 유형 | 인증 누락 |
| CWE | CWE-306 |
| 노출 | 원격 |
| 악용 가능성 | 높음 |
| 인증 필요 여부 | 아니요 |
| 필요한 권한 | 없음 |
| 사용자 상호 작용 | 없음 |