Impact
The vulnerability exists in the Panel Processor component of Oracle PeopleSoft Enterprise PeopleTools. An unauthenticated attacker with network access via HTTP can cause an update, insert or delete of data that the attacker is normally not authorized to modify, as well as read restricted data. The description explicitly states that successful attacks require human interaction from a person other than the attacker, indicating a social‑engineering component is needed. The impact is a compromise of data integrity and confidentiality for data exposed by the Panel Processor. This weakness is classified as CWE-285, Unauthorized Access.
Affected Systems
Oracle Corporation's PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected. All installations that expose the Panel Processor endpoint over HTTP are potentially vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 5.4 indicates moderate severity, affecting confidentiality and integrity. The EPSS score of <1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness via crafted HTTP requests to the Panel Processor endpoint; they need network access and the cooperation of a user other than the attacker.
OpenCVE Enrichment