一个影响 Oracle PeopleSoft Enterprise PeopleTools 的漏洞,允许远程攻击者在无需身份验证的情况下入侵易受攻击的系统。
CVE-2026-35273 是一个影响 Oracle PeopleSoft Enterprise PeopleTools 的 Updates Environment Management 组件的严重漏洞。
该漏洞可以通过网络远程利用,无需身份验证,可能导致:
| 产品 | 版本 |
|---|---|
| Oracle PeopleTools | 8.61 |
| Oracle PeopleTools | 8.62 |
Attack Vector : Network
Attack Complexity : Low
Privileges Required: None
User Interaction : None
Scope : Unchanged
Confidentiality : High
Integrity : High
Availability : High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
成功利用可能允许攻击者:
安全团队应监控以下内容:
Unexpected requests targeting:
- Environment Management endpoints
- Update services
- Administrative interfaces
cmd.exe
powershell.exe
bash
sh
python
perl
.jsp
.php
.asp
.aspx
.war
.jar
Unexpected outbound connections
Reverse shell behavior
Beaconing activity
将 PeopleTools 更新到 Oracle 的修复版本。
✓ Limit access to management interfaces
✓ Restrict trusted administrator IPs
✓ Use VPN access where possible
✓ Web server logs
✓ Process creation logs
✓ Authentication logs
✓ Network telemetry
搜索以下内容:
New administrator accounts
Unknown scheduled tasks
Suspicious web files
Unusual outbound traffic
本仓库提供用于:
它 不旨在促进对系统的未经授权访问或利用。
Oracle PeopleSoft PeopleTools — CVE-2026-35273
| 属性 | 值 |
|---|
| CVE | CVE-2026-35273 |
| 供应商 | Oracle |
| 产品 | PeopleSoft Enterprise PeopleTools |
| 严重性 | Critical |
| CVSS v3.1 | 9.8 |
| CWE | CWE-306 |
| 攻击向量 | Network |
| 身份验证 | Not Required |
| 用户交互 | None |
| 影响 | Remote Code Execution |
| 类别 | 详情 |
|---|
| 漏洞类型 | Missing Authentication |
| CWE | CWE-306 |
| 暴露程度 | Remote |
| 可利用性 | High |
| 需要身份验证 | No |
| 需要权限 | No |
| 用户交互 | No |