Impact
The vulnerability resides in the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools and permits an unauthenticated attacker to execute code via HTTP requests. Successful exploitation results in complete takeover of the PeopleSoft application, allowing the attacker to read, modify, or delete any data and disrupt service availability. The flaw demonstrates a severe breach of confidentiality, integrity, and availability and is classified as an Implicit Access Control weakness.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PT PeopleTools, specifically versions 8.61 and 8.62, are affected. These versions include the Performance Monitor component that is vulnerable to the described exploit.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests low current exploitation probability, yet the fact that the vulnerability is unauthenticated and reachable over HTTP makes it easily exploitable in environments where network segmentation is inadequate. The vulnerability is not listed in the CISA KEV catalog, but its impact warrants immediate attention. Attackers can leverage standard HTTP traffic to reach the exposed component, making the exploitation path straightforward when direct network access to the PeopleSoft instance is available.
OpenCVE Enrichment