Impact
This vulnerability permits a low‑privilege attacker with network access to HTTP requests against Oracle PeopleSoft Enterprise PeopleTools. Exploitation requires human interaction from a non‑attacker user, but once triggered the attacker can unauthorized update, insert or delete data and read a subset of accessible data. The impact is a compromise of integrity and confidentiality of PeopleSoft data, but does not provide complete system takeover.
Affected Systems
Oracle's PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 reflects moderate severity with confidentiality and integrity impacts. The EPSS score is below 1 %, indicating that the likelihood of public exploitation is very low at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely to occur over the network via HTTP, requiring low authentication privileges and the cooperation of a non‑attacker user.
OpenCVE Enrichment