CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6199

As cited

Copy frozen at (site build).

vulnerabilities

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM

A pre-authentication remote code execution (RCE) vulnerability in Oracle PeopleSoft PeopleTools exploits the Integration Broker's PSIGW gateway through server-side request forgery (SSRF) to execute arbitrary code within the application server's Java virtual machine (JVM). The attack bypasses authentication requirements and evades behavioral and network-based detection mechanisms.

Why it matters: Organizations running PeopleSoft PeopleTools are at risk of unauthorized code execution without credentials; practitioners should assess exposure and monitor for active exploitation attempts immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM

A pre-authentication remote code execution (RCE) vulnerability in Oracle PeopleSoft PeopleTools exploits the Integration Broker's PSIGW gateway through server-side request forgery (SSRF) to execute arbitrary code within the application server's Java virtual machine (JVM). The attack bypasses authentication requirements and evades behavioral and network-based detection mechanisms.

Why it matters: Organizations running PeopleSoft PeopleTools are at risk of unauthorized code execution without credentials; practitioners should assess exposure and monitor for active exploitation attempts immediately.

VendorsOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary