ORACLE PEOPLESOFT远程执行代码

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# Update **The article was updated on September 2018 with a more generic way to exploit the AXIS-SSRF combo**. You can scroll to the end of the article [here](https://www.ambionics.io/blog/oracle-peoplesoft-xxe-to-rce#axis-update). # Oracle PeopleSoft I had the chance, a few months ago, to audit several Oracle PeopleSoft solutions, including PeopleSoft HRMS and PeopleTool. Despite several undocumented CVEs, the Internet did not have much to offer on how to attack the software, except for the [very informative talk](https://erpscan.com/wp-content/uploads/presentations/2015-HITB-Amsterdam-Oracle-PeopleSoft-Applications-are-Under-Attack.pdf) from [ERPScan](https://erpscan.com/) at HITB from two years ago. From the slides, it was clear PeopleSoft was a nest of vulnerabilities, despite not having lots of public information about them. PeopleSoft applications contain a lot of different endpoints, many of which are unauthenticated. Many services also happen to use defaut passwords,...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息