Cyber Resilience

CVE-2023-21845

Oracle Peoplesoft Enterprise Peopletools 8.60

Published
18 January 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 5.4
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS Score 0.0040 33th percentile
Risk Priority 43 floored blend · peak EPSS

Summary

CVE-2023-21845 is a medium-severity an unspecified weakness vulnerability in Oracle Peoplesoft Enterprise Peopletools. Its CVSS base score is 5.4 (Medium).

Operationally, ranked at the 33th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). The supported version that is affected is 8.60. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks…

more

of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-53065Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2026-60152Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2026-47024Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2025-30697Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2023-21916Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2025-53048Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2025-30748Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2024-21214Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2025-61750Same product: Oracle Peoplesoft Enterprise Peopletools
CVE-2025-30747Same product: Oracle Peoplesoft Enterprise Peopletools

Affected Assets

oracle
peoplesoft enterprise peopletools
8.60

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References