Impact
PeopleSoft Enterprise CS Campus Community 9.2.38 contains a security flaw that allows an unauthenticated attacker to use the HTTP interface to read or modify data that should be protected. The vulnerability can lead to disclosure of confidential information and unauthorized updates, inserts or deletes, which may compromise business processes that rely on accurate PeopleSoft data. The weakness is identified as an improper access control flaw that grants users higher privileges than intended.
Affected Systems
The affected system is Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38. No other versions are reported as vulnerable in the current CNA data.
Risk and Exploitability
The CVSS v3.1 base score is 8.2, indicating a high severity of impact on confidentiality and moderate impact on integrity, while availability remains unaffected. The EPSS score is less than 1 %, suggesting a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers can reach the affected application over a public network via HTTP, and because no authentication is required they can execute the attack from any system that can connect to the web interface. The simplicity of the required traffic makes this an easily exploitable condition for adversaries with network access.
OpenCVE Enrichment