Impact
The vulnerability resides in the security component of Oracle PeopleSoft Enterprise CS Campus Community, allowing an unauthenticated attacker with network access over HTTP to read a limited subset of data that the application exposes. The weakness is a type‑III data‑leak (CWE‑200) that impacts confidentiality. This leads to confidentiality impacts, reflected in the CVSS 3.1 base score of 5.3, with the vector indicating no impact on integrity or availability.
Affected Systems
Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 is affected. No other versions or products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 denotes moderate severity, while the EPSS of less than 1% indicates a very low probability of current exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an HTTP request to the vulnerable component without authentication, meaning any user capable of reaching the application can exploit the weakness and obtain unauthorized read access to sensitive data.
OpenCVE Enrichment