Impact
The compromised PeopleSoft Enterprise CS Student Records module, specifically the Research Tracking component, allows an attacker with only low privileges and network access via HTTPS to create, delete, or modify critical data. The vulnerability can also provide unauthorized read access to all data available through the application, resulting in significant confidentiality and integrity damage.
Affected Systems
Oracle Corporation PeopleSoft Enterprise CS Student Records version 9.2.38 is affected; no other versions are listed as vulnerable in the provided data.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 indicates high severity, and the vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) shows that a remote attacker only needs HTTPS connectivity and low‑privilege credentials. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an attacker exploiting the Research Tracking functionality over HTTPS to gain data‑manipulation or read privileges without higher‑level authentication.
OpenCVE Enrichment