The I-Assure Vulnerability Research Team (VRT) has discovered several, previously unpublished vulnerabilities in the PeopleSoft (Oracle) PeopleTools application. PeopleTools provides developers the power and flexibility to enhance, deploy, and extend PeopleSoft and non-PeopleSoft applications.
Vulnerabilities were discovered while assessing PeopleTools for the Defense Integrated Military Human Resources System (DIMHRS). We are currently working with the vendor on two more discovered vulnerabilities that will be released to the general public shortly.
Our proactive VRT can assess your application for vulnerabilities before you fall victim to information disclosure or hacking activities. We utilize our experience and knowledge of system/application security to perform our assessment. Unlike other vulnerability assessment teams, we do NOT solely rely on automated tools to perform our assessment.
I-Assure has reported that PeopleTools is prone to an information disclosure vulnerability. The issue presents itself within the PeopleTools "grid" functionality...(more)
I-Assure has reported that PeopleTools is prone to an information disclosure vulnerability. The issue presents itself within the PeopleTools <Control><J> functionality...(more)
I-Assure has reported that PeopleTools is prone to a database upload. The issue presents itself within the PeopleTools LONGCHAR and VARCHAR database fields...(more)