Impact
The vulnerability in PeopleSoft Enterprise CS Campus Community 9.2.38 allows an unauthenticated attacker who can reach the application over HTTPS to gain full access to all data stored in the system, including confidential information. The CVSS 3.1 base score of 5.9 reflects a high confidentiality impact while integrity and availability remain unaffected. The attack vector involves network-level access without the need for user credentials.
Affected Systems
Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 is impacted. No other versions or editions are listed as affected in the available data.
Risk and Exploitability
With an EPSS score of less than 1 % and no listing in CISA’s KEV catalog, the likelihood of exploitation is low at present. However, the vulnerability can be leveraged over the public HTTPS interface by any remote host, requiring only a basic level of network reachability. The moderate CVSS score indicates potential damage if an attacker succeeds, and there are no known mitigations beyond patching and network restrictions.
OpenCVE Enrichment