Impact
The vulnerability is an improper access control flaw (CWE‑284) in the Integration and Interfaces component of Oracle PeopleSoft Enterprise CS Campus Community. Based on the description, it is inferred that a low‑privileged attacker who can reach the system over HTTP can craft requests that bypass authentication controls and execute code. The impact is full compromise of confidentiality, integrity, and availability, enabling the attacker to read, modify, delete data and disrupt service operation.
Affected Systems
Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 is the affected product. The vulnerable component is the Integration and Interfaces module, which exposes network‑reachable HTTP endpoints used in campus community deployments.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high‑severity vulnerability, with the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The EPSS score of less than 1 % and the absence from CISA’s KEV database suggest that no publicly documented exploitation has been observed. Nevertheless, the low privilege requirement and open HTTP interface mean that any actor on the network can potentially exploit the flaw, making the attack path straightforward and the risk significant until a vendor patch is applied.
OpenCVE Enrichment