Vulnerability record · CVE-2023-22047 · published 18 July 2023
CVE-2023-22047: Oracle PeopleSoft PeopleTools Portal missing authentication exposes data
Oracle · Peoplesoft Enterprise
Oracle PeopleSoft Enterprise PeopleTools (Portal component) versions 8.59 and 8.60 contain a missing-authentication flaw that lets an unauthenticated network attacker reach a critical function over HTTP. Successful exploitation gives unauthorized access to critical data or all PeopleSoft Enterprise PeopleTools accessible data, making it a serious confidentiality risk for exposed deployments.
Description
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.59 and 8.60. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable data disclosure with a 7.5 CVSS and very high EPSS, though no confirmed in-the-wild exploitation or KEV listing.
What it is
Oracle PeopleSoft Enterprise PeopleTools (Portal component) versions 8.59 and 8.60 contain a missing-authentication flaw that lets an unauthenticated network attacker reach a critical function over HTTP. Successful exploitation gives unauthorized access to critical data or all PeopleSoft Enterprise PeopleTools accessible data, making it a serious confidentiality risk for exposed deployments.
Impact
An attacker gains read access to critical PeopleSoft data, up to everything the PeopleTools instance can reach. There is no integrity or availability impact per the CVSS vector, so the loss is data disclosure.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any internet- or network-exposed PeopleSoft Portal endpoint is in scope.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged, but EPSS is very high at 0.7698 (99.5th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Apply the Oracle July 2023 Critical Patch Update for PeopleTools 8.59 and 8.60 immediately.
- Restrict network access to PeopleSoft Portal/HTTP endpoints to trusted networks or VPN; do not expose directly to the internet.
- Place authentication or a reverse proxy in front of Portal endpoints where feasible until patching is complete.
- Verify the patch level of all PeopleTools instances, including non-production and forgotten deployments.
- Monitor for anomalous unauthenticated requests to Portal paths after patching.
Detection
- Review HTTP access logs for unauthenticated requests to PeopleSoft Portal endpoints, especially unusual paths or high-volume enumeration.
- Alert on access to Portal resources from unexpected source IPs or geographies.
- Baseline normal Portal traffic and flag deviations in request patterns or response sizes suggesting data retrieval.
- Correlate PeopleSoft application logs with web server logs for access without a valid session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2023.html | PatchVendor Advisory |
| https://www.oracle.com/security-alerts/cpujul2023.html | PatchVendor Advisory |
Track CVE-2023-22047 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-22047), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.