Impact
The vulnerability in Oracle PeopleSoft Enterprise HCM Human Resources allows a high‑privileged attacker with network access via HTTP to exploit the Job Profile Manager component and create, delete, or modify critical data, or gain full access to all accessible data. The flaw can be leveraged without user interaction and compromises confidentiality and integrity.
Affected Systems
Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 is affected. No other versions or vendor products are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates moderate severity, with high‑privileged authentication required and no user interaction. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need network access to the HTTP interface of the PeopleSoft instance and possession of application‑level credentials or privileges that exceed normal user rights. Because the flaw permits direct manipulation of critical data, a successful exploit could lead to significant confidentiality and integrity impact for the affected organization.
OpenCVE Enrichment