← Vulnerability feed

Vulnerability record · CVE-2023-22047 · published 18 July 2023

CVE-2023-22047: Oracle PeopleSoft PeopleTools Portal missing authentication exposes data

Oracle · Peoplesoft Enterprise

Oracle PeopleSoft Enterprise PeopleTools (Portal component) versions 8.59 and 8.60 contain a missing-authentication flaw that lets an unauthenticated network attacker reach a critical function over HTTP. Successful exploitation gives unauthorized access to critical data or all PeopleSoft Enterprise PeopleTools accessible data, making it a serious confidentiality risk for exposed deployments.

7.5 CVSS 3.1 High EPSS 77% · top 0.5% CWE-306 · Missing authentication for critical function
7.5CVSS 3.1 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-reachable data disclosure with a 7.5 CVSS and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.

What it is

Oracle PeopleSoft Enterprise PeopleTools (Portal component) versions 8.59 and 8.60 contain a missing-authentication flaw that lets an unauthenticated network attacker reach a critical function over HTTP. Successful exploitation gives unauthorized access to critical data or all PeopleSoft Enterprise PeopleTools accessible data, making it a serious confidentiality risk for exposed deployments.

Impact

An attacker gains read access to critical PeopleSoft data, up to everything the PeopleTools instance can reach. There is no integrity or availability impact per the CVSS vector, so the loss is data disclosure.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed PeopleSoft Portal endpoint is in scope.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high at 0.7698 (99.5th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Apply the Oracle July 2023 Critical Patch Update for PeopleTools 8.59 and 8.60 immediately.
  • Restrict network access to PeopleSoft Portal/HTTP endpoints to trusted networks or VPN; do not expose directly to the internet.
  • Place authentication or a reverse proxy in front of Portal endpoints where feasible until patching is complete.
  • Verify the patch level of all PeopleTools instances, including non-production and forgotten deployments.
  • Monitor for anomalous unauthenticated requests to Portal paths after patching.

Detection

  • Review HTTP access logs for unauthenticated requests to PeopleSoft Portal endpoints, especially unusual paths or high-volume enumeration.
  • Alert on access to Portal resources from unexpected source IPs or geographies.
  • Baseline normal Portal traffic and flag deviations in request patterns or response sizes suggesting data retrieval.
  • Correlate PeopleSoft application logs with web server logs for access without a valid session.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-22047 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2131Oracle peoplesoft enterprise vulnerabilityUnspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.22.14, 8.47.12, and 8.48.08 has unknown impact and attack vectors, aka PSE…EPSS 3.0%10.0CVE-2007-2132Oracle peoplesoft enterprise vulnerabilityUnspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.47.12 and 8.48.08 has unknown impact and attack vectors, aka…EPSS 2.2%10.0CVE-2007-2133Oracle peoplesoft enterprise vulnerabilityUnspecified vulnerability in the PeopleSoft Enterprise Human Capital Management component in Oracle PeopleSoft Enterprise 8.9 has unknown impact and …EPSS 2.2%10.0CVE-2006-5375Oracle peoplesoft enterprise vulnerabilityMultiple unspecified vulnerabilities in PeopleTools component in Oracle PeopleSoft Enterprise 8.46 GA, 8.47 GA, 8.48 GA, 8.46.15, 8.47.09, and 8.48.0…EPSS 2.9%10.0CVE-2006-3722Oracle peoplesoft enterprise vulnerabilityUnspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.4 Bundle #16, 8.8 Bundle #10, and 8.9 Bundle #3 h…EPSS 4.1%10.0CVE-2006-3723Oracle peoplesoft enterprise vulnerabilityUnspecified vulnerability in PeopleSoft Enterprise Portal for Oracle PeopleSoft Enterprise Portal 8.8 with Enforcer Portal Pack Bundle #10 and 8.9 Bu…EPSS 4.1%10.0CVE-2006-1886Oracle peoplesoft enterprise vulnerabilityUnspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.46.12 and 8.47.04 has unknown impact and attack vectors, aka…EPSS 3.9%10.0CVE-2005-3462Oracle peoplesoft enterprise vulnerabilityUnspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.44 up to 8.46.02 has unknown impact and attack vectors, as identified by O…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2023-22047), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.