Premier Ministre S.G.D.S.N Agence nationalede la sécurité dessystèmes d'information Paris, le 16 septembre 2026 N° CERTFR-2026-AVI-1187 Affaire suivie par: CERT-FR Avis du CERT-FR Objet: Multiples vulnérabilités dans Oracle PeopleSoft Gestion du document Référence CERTFR-2026-AVI-1187 Titre Multiples vulnérabilités dans Oracle PeopleSoft Date de la première version16 septembre 2026 Date de la dernière version16 septembre 2026 Source(s) Bulletin de sécurité Oracle PeopleSoft cspusep2026 du 15 septembre 2026 Une gestion de version détaillée se trouve à la fin de ce document. Risques Atteinte à l'intégrité des données Atteinte à la confidentialité des données Déni de service à distance Exécution de code arbitraire à distance Systèmes affectés PeopleSoft Enterprise CC Common Application Objects version 9.2 PeopleSoft Enterprise FIN Engineering Brazil version 9.1 PeopleSoft Enterprise FIN Inventory Brazil version 9.1 PeopleSoft Enterprise PeopleTools versions 8.61 à 8.63 PeopleSoft Enterprise PRTL Interaction Hub version 9.1 Résumé De multiples vulnérabilités ont été découvertes dans Oracle PeopleSoft. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Solutions Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation). Documentation Bulletin de sécurité Oracle PeopleSoft cspusep2026 du 15 septembre 2026 https://www.oracle.com/security-alerts/cspusep2026.html Référence CVE CVE-2023-48795 https://www.cve.org/CVERecord?id=CVE-2023-48795 Référence CVE CVE-2023-6918 https://www.cve.org/CVERecord?id=CVE-2023-6918 Référence CVE CVE-2026-25639 https://www.cve.org/CVERecord?id=CVE-2026-25639 Référence CVE CVE-2026-73954 https://www.cve.org/CVERecord?id=CVE-2026-73954 Référence CVE CVE-2026-73955 https://www.cve.org/CVERecord?id=CVE-2026-73955 Référence CVE CVE-2026-73960 https://www.cve.org/CVERecord?id=CVE-2026-73960 Référence CVE CVE-2026-7598 https://www.cve.org/CVERecord?id=CVE-2026-7598 Référence CVE CVE-2026-82993 https://www.cve.org/CVERecord?id=CVE-2026-82993 Référence CVE CVE-2026-83014 https://www.cve.org/CVERecord?id=CVE-2026-83014 Référence CVE CVE-2026-83015 https://www.cve.org/CVERecord?id=CVE-2026-83015 Référence CVE CVE-2026-83016 https://www.cve.org/CVERecord?id=CVE-2026-83016 Référence CVE CVE-2026-83017 https://www.cve.org/CVERecord?id=CVE-2026-83017 Référence CVE CVE-2026-83018 https://www.cve.org/CVERecord?id=CVE-2026-83018 Référence CVE CVE-2026-83019 https://www.cve.org/CVERecord?id=CVE-2026-83019 Référence CVE CVE-2026-83070 https://www.cve.org/CVERecord?id=CVE-2026-83070 Référence CVE CVE-2026-83147 https://www.cve.org/CVERecord?id=CVE-2026-83147 Référence CVE CVE-2026-83420 https://www.cve.org/CVERecord?id=CVE-2026-83420 Référence CVE CVE-2026-87264 https://www.cve.org/CVERecord?id=CVE-2026-87264 Gestion détaillée du document le 16 septembre 2026 Version initiale