Impact
A vulnerability in the Australian Features component of Oracle PeopleSoft Enterprise CS Student Records allows a low‑privileged attacker with network access via HTTP to compromise the entire application. The flaw is highly exploitable (CVSS 3.1 base score 8.8) and can result in full compromise, exposing or altering sensitive student records, and disrupting service availability.
Affected Systems
Oracle PeopleSoft Enterprise CS Student Records version 9.2.38 is affected. This applies to installations of the PeopleSoft Enterprise CS Student Records product that include the Australian Features component.
Risk and Exploitability
The vulnerability is exploitable over the public network (AV:N) with a low attack complexity (AC:L) and requires low privilege (PR:L). No user interaction is required (UI:N). The EPSS score indicates a very low probability of exploitation (less than 1 percent). The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score and network accessibility make it a significant risk if left unpatched.
OpenCVE Enrichment