Tag: oracle
Oracle PeopleSoft RCE Flaw Allows Auth Bypass via Deserialization
A deserialization vulnerability in Oracle PeopleSoft's HubMBeanPersistance method enables remote code execution, with the built-in authentication requirement undermined by a bypass condition.
Oracle PeopleSoft SSRF Flaw Requires No Auth, Scores 9.3 CVSS
A server-side request forgery vulnerability in Oracle PeopleSoft's HttpListeningConnector can be exploited by unauthenticated remote attackers and chained with other bugs to…
Critical Oracle E-Business Suite Flaw Under Active Exploitation
Attackers are actively exploiting CVE-2026-46817, a critical unauthenticated takeover vulnerability in Oracle E-Business Suite, weeks after Oracle shipped a patch in its…
Nissan Employee Data Breach Tied to Oracle PeopleSoft Zero-Day Attacks
Nissan has disclosed a breach of current and former employee records after ShinyHunters exploited a critical zero-day in Oracle PeopleSoft, part of…