Impact
Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 contains an easily exploitable vulnerability within the Integration and Interfaces component. A high‑privileged attacker with HTTPS network access can gain the ability to create, delete or modify critical data, as well as read all data exposed by the application. The vulnerability leads to confidentiality and integrity loss but does not directly impact availability.
Affected Systems
The affected product is Oracle Corporation’s PeopleSoft Enterprise CS Campus Community, specifically version 9.2.38. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS 3.1 score of 6.5 reflects moderate to high severity, and the low EPSS score (<1%) indicates that exploitation is currently unlikely but not impossible. The attack vector is inferred to be network based over HTTPS, requiring the attacker to possess high‑privilege credentials or exploit a privilege escalation flaw. Because the vulnerability is not listed in the CISA KEV catalog, no known widespread exploits have been reported, yet the impact if exploited is significant for organizations relying on the affected PeopleSoft deployment.
OpenCVE Enrichment