Impact
The vulnerability allows an unauthenticated attacker over HTTP to view critical data in Oracle PeopleSoft Enterprise CS Student Records. It causes a confidentiality breach without affecting integrity or availability. The CVSS 3.1 score of 7.5 reflects the high confidentiality impact and the fact that no authentication is required to exploit it.
Affected Systems
PeopleSoft Enterprise CS Student Records version 9.2.38 from Oracle Corporation is affected. No other versions or vendors are listed.
Risk and Exploitability
The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. However, because the attack can be performed remotely via HTTP without credentials, the risk to affected installations remains significant. An attacker could gain read access to all available PeopleSoft data, potentially exposing sensitive student records.
OpenCVE Enrichment