Impact
A vulnerability exists in the PeopleSoft Enterprise CS Student Records product, specifically within the Research Tracking component of Oracle PeopleSoft. The defect enables an attacker who has only low privilege and network access via HTTPS to create, delete, or modify critical data, or otherwise gain unauthorized access to all data accessible through the application. The impact is severe to confidentiality and integrity, with a CVSS 3.1 Base Score of 8.1. The vector indicates that the attacker only needs network connectivity to the application’s HTTPS interface; no additional credentials or local access are required.
Affected Systems
Oracle Corporation PeopleSoft Enterprise CS Student Records version 9.2.38 is affected. No other versions are listed as vulnerable in the provided data.
Risk and Exploitability
The CVSS score of 8.1 reflects high severity while the EPSS score of less than 1% suggests that, at present, exploitation is not widespread. The vulnerability is not included in the CISA KEV catalog. The likely attack path involves a remote attacker using HTTPS to interact with the Research Tracking module under low privilege. If exploited, the attacker could compromise confidentiality and integrity of the entire Student Records database.
OpenCVE Enrichment