漏洞描述 Oracle PeopleSoft是一款功能强大的企业级应用软件,主要用于支持企业的核心业务流程,包括人力资源管理、财务管理、供应链管理、客户关系管理等多个领域,该产品OraclePeopleSoft HttpListeningConnector接口存在XXE漏洞,攻击者可以有效对系统业务进行信息探索
相关漏洞推荐 Oracle E-Business Suite /OA_HTML/jtfwrepo.xml 敏感信息泄漏漏洞 无POC 2025-09-01 | Oracle E-Business Suite Oracle E-Business Suite存在信息泄露漏洞,攻击者可以利用该漏洞获取大量敏感信息,以供下一步的攻击使用。 CVE-2020-14750: Oracle WebLogic Server - Remote Command Execution POC 2025-09-01 | Oracle WebLogic Server Oracle WebLogic Server 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0 is susceptible ... CVE-2020-14883: Oracle Fusion Middleware WebLogic Server Administration Console - Remote Code Execution POC 2025-09-01 | Oracle Fusion Middleware WebLogic Server Administration Console The Oracle Fusion Middleware WebLogic Server admin console in versions 10.3.6.0.0, 12.1.3.0.0, 12.2.... CVE-2013-1965: Apache Struts2 S2-012 RCE POC 2025-09-01 | Apache Struts2 Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote ... CVE-2013-2251: Apache Struts 2 - DefaultActionMapper Prefixes OGNL Code Execution (S2-016) POC 2025-09-01 | Apache Struts 2 In Struts 2 before 2.3.15.1 the information following "action:", "redirect:", or...