Impact
A flaw in the Commonline Loans component of PeopleSoft Enterprise CS Financial Aid allows a low‑privileged attacker with standard HTTP access to create, delete, or modify critical data, and to read all data available through PeopleSoft. The vulnerability, classified as CVSS 3.1 vector AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N, indicates significant confidentiality and integrity impacts while availability is unaffected. The low privileges required mean that a threat actor does not need elevated system credentials to exploit the issue. This issue is an instance of CWE‑284, improper authorization, allowing unauthorized actions.
Affected Systems
Oracle PeopleSoft Enterprise CS Financial Aid, version 9.2.38, is the confirmed affected release. The vulnerability resides in the Commonline Loans component and is specific to the HTTP interface exposed by the system.
Risk and Exploitability
The CVSS base score of 6.8 places the flaw in the medium severity range, yet the EPSS score of less than 1% indicates a low probability of exploitation in the wild as of this analysis. The vulnerability is not listed in CISA’s KEV catalog. The CVE data does not indicate that exploitation is actively occurring. Because the attack vector is purely over the network and requires only low privileges, organizations that expose PeopleSoft to external networks or have insufficient internal access controls should consider the risk high relative to their cybersecurity posture.
OpenCVE Enrichment