Impact
The vulnerability resides in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records 9.2.38 and permits a high‑privileged attacker with network access through HTTP to compromise the application. Successful exploitation provides an attacker with full control over the system, affecting confidentiality, integrity, and availability. The CWE identifier for this weakness reflects improper access control.
Affected Systems
Oracle PeopleSoft Enterprise CS Student Records version 9.2.38 is affected, as disclosed in the advisory. No other versions are specified as impacted.
Risk and Exploitability
The CVSS v3.1 Base Score of 6.6 indicates moderate severity with high confidentiality, integrity, and availability impacts. The EPSS score is less than 1 % and the vulnerability is not listed in CISA KEV, suggesting a low current exploitation probability. The attack vector is normal HTTP traffic to the web interface; the brief description claims the exploit is difficult to execute and requires high network privileges, implying a skilled adversary with sufficient access would need to deliver the exploit.
OpenCVE Enrichment