Impact
The vulnerability resides in the PeopleSoft Enterprise CS Campus Community component that handles person data. It is an authorization flaw (CWE-284) that allows an attacker with low privileges who can reach the system over HTTP to create, delete, or modify critical records, read data beyond authorized scope, and trigger application hangs or crashes.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise CS Campus Community, version 9.2.38. No other versions or subcomponents are reported as affected. The issue specifically concerns the Person Data module.
Risk and Exploitability
The CVSS base score of 7.1 reflects moderate to high severity driven by the authorization weakness identified as CWE-284, which impacts confidentiality, integrity, and availability. The EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV, suggesting no known widespread attacks. Exploitation requires only low privileges and network access over HTTP, making the attack path relatively simple but still risky because it can compromise data integrity, availability, and, to a lesser extent, confidentiality.
OpenCVE Enrichment