Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2026.html |
|
Wed, 22 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics |
ssvc
|
Wed, 22 Apr 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | PeopleSoft Employee Snapshot Vulnerability Allows Unauthorized Data Modification | |
| Weaknesses | CWE-284 |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapshot). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise HCM Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N). | |
| First Time appeared |
Oracle
Oracle peoplesoft Enterprise Hcm Human Resources |
|
| CPEs | cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle peoplesoft Enterprise Hcm Human Resources |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-04-22T14:14:22.474Z
Reserved: 2026-01-05T18:07:34.726Z
Link: CVE-2026-22006
Updated: 2026-04-22T14:14:14.831Z
Status : Received
Published: 2026-04-21T21:16:26.240
Modified: 2026-04-22T15:16:12.557
Link: CVE-2026-22006
No data.
OpenCVE Enrichment
Updated: 2026-04-22T05:30:09Z