Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpuapr2026.html |
|
Mon, 27 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High‑Privilege HTTP Access Allows Unauthorized Data Modification in Oracle PeopleSoft HCM 9.2 | |
| Weaknesses | CWE-269 |
Wed, 22 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
ssvc
|
Wed, 22 Apr 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | High‑Privilege HTTP Access Allows Unauthorized Data Modification in Oracle PeopleSoft HCM 9.2 | |
| Weaknesses | CWE-269 |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Job Profile Manager). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Human Resources. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise HCM Human Resources accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise HCM Human Resources accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N). | |
| First Time appeared |
Oracle
Oracle peoplesoft Enterprise Hcm Human Resources |
|
| CPEs | cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_human_resources:9.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle peoplesoft Enterprise Hcm Human Resources |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-04-22T14:20:08.398Z
Reserved: 2026-03-26T19:48:45.675Z
Link: CVE-2026-34280
Updated: 2026-04-22T14:20:03.367Z
Status : Analyzed
Published: 2026-04-21T21:16:32.340
Modified: 2026-04-23T15:07:57.687
Link: CVE-2026-34280
No data.
OpenCVE Enrichment
Updated: 2026-04-27T19:45:11Z