Impact
A flaw in the Communication component of Oracle PeopleSoft Enterprise CS Campus Community (version 9.2.38) lets a low‑privileged attacker with network access over HTTPS read critical data or potentially all data available to the application. The vulnerability produces a confidentiality impact as reflected by a CVSS 3.1 score of 6.5, with the attack vector listed as network and the requirement for a low privileged user.
Affected Systems
The issue affects Oracle Corporation’s PeopleSoft Enterprise CS Campus Community product, specifically version 9.2.38 of the Communication module.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests that widespread exploitation is unlikely at present. The vulnerability is not included in the CISA KEV catalog, but an attacker who can reach the HTTPS interface may exploit the flaw to gain unauthorized data access. No additional exploitation steps are required beyond possessing low‑privilege credentials or access to the networked HTTPS endpoint.
OpenCVE Enrichment