Security readout for executives and security teams
Plain-English summary
This flaw affects Oracle PeopleSoft PeopleTools rich text editor in versions 8.57, 8.58, and 8.59. An unauthenticated attacker reachable over HTTP could abuse it if they can get another person to interact. Impact is limited data reading and limited unauthorized data changes, not system takeover or outage based on the provided CVSS.
Executive priority
Treat this as a near-term business risk, not an emergency absent exploitation evidence. Prioritize faster if PeopleSoft stores HR, payroll, financial, or identity data, or if HTTP access is broadly exposed.
Technical view
CVE-2021-35568 is a network-accessible PeopleSoft Enterprise PeopleTools vulnerability in the Rich Text Editor component. CVSS 3.1 is 6.1: low attack complexity, no privileges required, user interaction required, changed scope, low confidentiality and integrity impact, and no availability impact. No CWE is provided in the source bundle.
Likely exposure
Organizations running Oracle PeopleSoft Enterprise PT PeopleTools 8.57, 8.58, or 8.59 are in scope, especially where PeopleSoft HTTP services are reachable by users or externally exposed.
Exploitation context
The source bundle does not show CISA KEV listing or active exploitation. Exploitation requires network access via HTTP and human interaction by someone other than the attacker, reducing immediacy but keeping phishing-style abuse plausible.
Researcher notes
Evidence is limited to official CVE details and Oracle CPU reference. The bundle names the affected component and versions but does not include CWE, exploit details, indicators of compromise, or exact fixed build numbers.
Mitigation direction
- Review Oracle’s October 2021 Critical Patch Update for PeopleSoft guidance.
- Apply vendor-recommended PeopleTools security updates for affected versions.
- Restrict HTTP access to PeopleSoft to trusted networks where possible.
- Prioritize remediation for internet-facing or high-sensitivity PeopleSoft environments.
Validation and detection
- Inventory PeopleTools versions and identify any 8.57, 8.58, or 8.59 systems.
- Confirm whether Oracle October 2021 CPU fixes are installed.
- Map PeopleSoft HTTP exposure across internet, VPN, and internal networks.
- Review PeopleSoft logs for unusual data reads or modification activity.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-35568 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.1 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N2.82.7Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.1MediumVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://www.oracle.com/security-alerts/cpuoct2021.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
