Impact
This vulnerability describes a low‑privilege flaw within the Panel Processor component of Oracle PeopleSoft Enterprise PeopleTools 8.62. An attacker who can reach the application over HTTP may persuade an unrelated user to provide input that triggers unauthorized update, insert, or delete actions or to read protected data. The vulnerability is confined to confidentiality and integrity, as neutral availability is not affected.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools version 8.62 is the only public release identified as affected. Because the vulnerability exists in a core component that shares the application database, compromising PeopleTools can also influence other PeopleSoft products that depend on the same data store.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate severity; the low availability impact and requirement for human interaction lessen the likelihood of exploitation but do not eliminate it. EPSS is below 1 %, pointing to a very low probability of public exploitation, and the vulnerability is not listed in CISA KEV. Nevertheless, the combination of network reachability, low privilege, and social‑engineering tactics creates a realistic risk for insider or phishing attacks that could lead to data tampering or leakage.
OpenCVE Enrichment