Impact
The vulnerability resides in the Deployment Package component of Oracle PeopleSoft Enterprise PT PeopleTools. An attacker with high privileges who has logged into the underlying infrastructure can exploit this flaw, resulting in the complete takeover of PeopleSoft Enterprise PT PeopleTools. The impact extends beyond confidentiality, integrity, and availability of the affected product due to the potential scope change to related applications.
Affected Systems
Oracle Corporation PeopleSoft Enterprise PT PeopleTools versions 8.61 and 8.62 are affected. No additional affected versions are listed in the current CNA data.
Risk and Exploitability
The CVSS base score of 8.2 indicates high severity, and the vector shows that the attack requires local access (AV:L), low attack complexity (AC:L), high privileges (PR:H) with no user interaction (UI:N). The EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, because the flaw allows full control of the application and may affect other integrated products, it should be treated as a critical risk if the local infrastructure is compromised.
OpenCVE Enrichment