Impact
A flaw in the Process Scheduler component of Oracle PeopleSoft Enterprise PeopleTools permits a low‑privileged attacker with network access via HTTP to read, modify, create, or delete critical data. The vulnerability is an improper authorization weakness (CWE-284) that allows unauthorized creation, deletion or modification of data, and complete access to all PeopleSoft data accessible through the system. It requires a human user other than the attacker to interact with the system, and it directly compromises confidentiality and integrity of the affected database records.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 contain the vulnerable Process Scheduler component. While the flaw resides in PeopleSoft, it may also affect other PeopleSoft products that rely on the same scheduler infrastructure.
Risk and Exploitability
The CVSS base score of 8.7 signals a high‑risk vulnerability, yet the EPSS score of less than 1% suggests that exploitation has been rare to date. The vulnerability is not listed in the CISA KEV catalog, indicating no documented exploitation. The likely attack vector is inferred to be a network‑based HTTP request to the Process Scheduler when the attacker has low privileges and a separate human user interacts with the system. This operational effort is moderate, but successful exploitation could cause significant data loss or compromise.
OpenCVE Enrichment