Impact
The reported flaw exists in the Security component of PeopleSoft Enterprise CS Campus Community and allows an attacker to perform unauthenticated data creation, deletion, modification, and read operations over HTTP. The vulnerability permits unauthorized access to critical data, potentially exposing sensitive information and compromising data integrity, despite providing only low confidentiality impact as defined by the CVSS vector. An attacker could alter or delete data without authentication, leading to significant business disruption. The CVSS 3.1 Base Score of 6.5 indicates moderate severity with confidentiality changed low and integrity high, with no impact on availability.
Affected Systems
Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 is affected. The flaw is tied to the Security component of the application, and only this release is impacted. Systems running this version without the forthcoming patch remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 signals a moderate risk, and the EPSS score of less than 1% indicates exploitation is unlikely in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Attackers would need network access to the application server’s HTTP interface and can exploit the flaw without any authentication or user interaction. Given the lack of higher AV or UI vectors, the attack surface is limited to network-facing endpoints, but any compromise of these endpoints could lead to unauthorized data manipulation.
OpenCVE Enrichment