Impact
A vulnerability exists in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records. The weakness is identified as Improper Access Control (CWE-284). The flaw permits a low‑privileged attacker with network access over HTTP to compromise the application. Successful exploitation can result in full takeover of the PeopleSoft system, compromising confidentiality, integrity, and availability of all data and services. Based on the description, it is inferred that the attacker can gain control of the application.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise CS Student Records version 9.2.38 is affected. All deployments of this exact build are at risk.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 reflects a high impact severity. Attack complexity is high and required privileges are low, making exploitation somewhat difficult. The EPSS score is below 1 %, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to reach the application over HTTP and supply crafted input to the exposed Research Tracking endpoints.
OpenCVE Enrichment