Impact
The vulnerability is tied to the Security component of PeopleSoft Enterprise PeopleTools. An attacker with low privileges and network access over HTTP can conduct the exploit. The flaw permits the attacker to perform unauthorized update, insert or delete operations and read restricted data. These actions compromise the confidentiality and integrity of PeopleSoft data but do not affect availability. The weakness is reachable only through human interaction with a user other than the attacker.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools 8.61 and 8.62 are impacted. The products include the PeopleSoft application suite that handles enterprise data. No other versions or vendors are currently listed as affected. Systems running the specified versions must be evaluated for exposure.
Risk and Exploitability
With a CVSS base score of 5.4 the risk is classified as medium severity. The EPSS score is less than 1 %, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based HTTP, requiring low attacker privileges and user interaction from a different individual. The ability to modify or read protected data makes the vulnerability valuable to attackers especially if the end user is a privileged account holder. The description notes a scope change, indicating that successful exploitation may affect additional products beyond PeopleSoft alone.
OpenCVE Enrichment