Impact
A flaw in Oracle PeopleSoft Enterprise PeopleTools’ OpenSearch Dashboards component permits an unauthenticated attacker to exploit the web interface over HTTP. The vulnerability does not require prior authentication but does require a human to interact with the GUI, allowing the attacker to compromise administrative processes and potentially gain access to all data stored in the PeopleSoft database. The primary consequence is the confidential disclosure of critical business information, as the CVSS vector indicates no privileges are needed and only user interaction is required.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected. The weakness resides in the OpenSearch Dashboards module of these releases. No other vendors or product lines are listed as impacted.
Risk and Exploitability
The CVSS base score of 7.4 places this issue in the high‑to‑critical severity range. However, the EPSS score of less than 1% suggests it is currently unlikely to see widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, but the scope change clause means that a successful compromise could impact additional PeopleSoft applications linked to the affected component. An attacker would need network access to the affected HTTP service and a human user to initiate the exploit, reducing immediate threat but remaining a significant risk if daily operations require user interaction with the dashboards.
OpenCVE Enrichment