Impact
This vulnerability resides in the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools 8.62. It is a type of open redirect flaw (CWE‑601), allowing an unauthenticated attacker with network access over HTTP to compromise PeopleSoft Enterprise PeopleTools. The flaw requires human interaction with a person other than the attacker, implying a social‑engineering component. Once exploited, an attacker can perform unauthorized insert, update, or delete operations on sensitive data, read restricted records, and induce a partial denial of service. The impact spans confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation PeopleSoft Enterprise PeopleTools version 8.62 is the specific product listed as vulnerable. The flaw affects the PIA Core Technology component, and while the primary target is this product, other Oracle PeopleSoft installations that rely on the same component could also be exposed.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates high severity. The EPSS score is below 1 % and the vulnerability is not in the CISA KEV catalog, suggesting low overall exploitation likelihood. However, the attack vector is network‑based over HTTP, requires no authentication, and depends on user interaction with a third party. Because the flaw can lead to data tampering, disclosure, and partial service disruption, the potential damage remains significant, warranting prompt remediation.
OpenCVE Enrichment