Impact
A flaw in the Performance Monitor component of Oracle PeopleSoft Enterprise PT PeopleTools allows an unauthenticated attacker with network access through HTTP to gain full control over the application. The vulnerability can lead to a complete takeover, compromising confidentiality, integrity, and availability. It is classified as a high‑severity issue with a CVSS v3.1 Base Score of 8.1, indicating that a successful exploit can result in remote code execution and system compromise.
Affected Systems
Affected versions are Oracle PeopleSoft Enterprise PT PeopleTools 8.61 and 8.62. Any installation of these releases is vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.1 points to significant risk, while the EPSS score of less than 1% suggests that exploitation is not yet widespread. The vulnerability is not listed in CISA’s KEV catalog, indicating no known public exploits. The attack vector is inferred to be remote over HTTP, requiring no authentication, and requires an attacker to be able to send HTTP requests to the application. Successful exploitation would grant the attacker full control over the PeopleSoft instance.
OpenCVE Enrichment