Impact
This vulnerability is located in the PIA Core Technology component of Oracle PeopleSoft Enterprise PeopleTools. An attacker who already has high‑privileged credentials and can reach the application over HTTP can exploit the flaw to read any data that should be protected, essentially providing the same visibility as a legitimate high‑privileged user. The impact is a confidentiality breach that could expose critical business information.
Affected Systems
The affected product is Oracle PeopleSoft Enterprise PeopleTools, specifically the 8.61 and 8.62 releases. Customers running either of these versions are at risk.
Risk and Exploitability
The CVSS 3.1 base score of 4.9 indicates a moderate severity with a confidentiality impact. The EPSS score of less than 1% suggests a very low likelihood of active exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires network access via HTTP and the attacker must already possess high‑privileged credentials; there is no reported denial of service or integrity impact.
OpenCVE Enrichment