Impact
The vulnerability resides in the Billing component of Oracle PeopleSoft Enterprise CS Student Financials and can be exploited by a low‑privileged attacker who has network connectivity to the HTTP interface. Successful exploitation results in a full compromise of the application, providing the attacker with complete control and exposing all sensitive information. The CVSS 3.1 score of 8.8 reflects severe impacts to confidentiality, integrity, and availability.
Affected Systems
The affected product is Oracle PeopleSoft Enterprise CS Student Financials version 9.2.38, specifically the Billing component, as identified by the supplied CPE string. No other versions or products are listed as impacted.
Risk and Exploitability
Although the EPSS score is less than 1%, indicating a low probability of observed exploitation, the vulnerability is highly exploitable via HTTP without authentication and can be leveraged by anyone with network access. It is not currently listed in CISA’s KEV catalog, but its high CVSS score and the nature of the attack vector warrant urgent attention.
OpenCVE Enrichment