Impact
A flaw in Oracle PeopleSoft Enterprise CC Common Application Objects version 9.2 allows an attacker to create, delete, or modify critical data without authentication, and to read all accessible data. This results in complete loss of confidentiality and integrity for affected records, while availability is not directly harmed. The vulnerability is an authorization bypass, exploiting improper access controls exposed over HTTP.
Affected Systems
Oracle Corporation PeopleSoft Enterprise CC Common Application Objects 9.2 is the only version affected; no other variants or versions are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 9.1 indicates maximum severity for confidentiality and integrity impacts. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated attacker sending HTTP requests to the PeopleSoft application, exploiting the improper access control to reach protected data and functions.
OpenCVE Enrichment