One encoded path byte bypasses PeopleSoft’s literal WAF rule, and attackers are deploying web shells again.
The route reaches unpatched PSEMHUB deployments that operators protected only with a literal-path WAF or reverse-proxy rule.
Oracle PeopleSoft Enterprise PeopleTools, enterprise application servers commonly deployed on Windows or Linux with a WebLogic web tier.
Unauthenticated command execution and persistent web-shell deployment through PeopleSoft installations operators believed were protected by path-based WAF rules
The change is not another description of the deserialization flaw; it is evidence that the perimeter mitigation fails during ongoing exploitation on dozens of systems.
Detail and 2 sources
A request to /%50SEMHUB/hub is checked in encoded form at the perimeter, decoded by WebLogic, and routed to the vulnerable servlet. Deserialization then executes commands as the PeopleSoft or WebLogic service account.
Observed follow-on activity includes JSP web shells, fileless commands, tunnels, and remote-management tooling. Oracle has published fixes for supported affected versions.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Reaches end-of-life hardware
- No
Google attributes the encoded-path bypass to systems protected only by literal WAF rules and explicitly distinguishes them from patched systems; it does not show that the Oracle patch itself is bypassed.