Impact
A vulnerability in the Security component of Oracle PeopleSoft Enterprise CS Campus Community allows an unauthenticated network attacker to exploit the system over HTTP. Successful exploitation can lead to unauthorized read access to critical data, full access to all data available in the application, and the ability to insert, update, or delete data that the attacker should not have permission to modify. The impact on confidentiality is high while integrity is moderate as indicated by the CVSS vector. The vulnerability is difficult to exploit but does not require any authentication or special user privileges.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise CS Campus Community (version 9.2.38) is impacted. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 shows moderate severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote over HTTP from the network due to the unauthenticated nature of the exploit. No mitigation or patch is currently noted, so the risk largely depends on network exposure and the absence of patches.
OpenCVE Enrichment