Impact
Vulnerability in the Global Payroll for Switzerland component of Oracle PeopleSoft Enterprise HCM Global Payroll Switzerland enables a low‑privilege attacker with network access over HTTP to create, delete, or modify critical payroll data. The flaw permits the attacker to gain unauthorized access to or complete control over all data within the affected system, leading to loss of confidentiality and integrity. The weakness is rooted in improper authorization controls in the application, allowing privileges that should be restricted.
Affected Systems
This issue affects Oracle Corporation PeopleSoft Enterprise HCM Global Payroll Switzerland, specifically version 9.2. No other versions or variants are listed as impacted; however, the description notes that the vulnerability could have a scope change that might affect additional PeopleSoft products.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 reflects high confidentiality and integrity impact with a scope change, and an attack complexity of high, indicating that while effort is required, the risk remains significant. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild at present. Because the flaw is not listed in the CISA KEV catalog, there is no known active exploitation. The likely attack vector is over network HTTP, with the attacker requiring only low privileges. Successful exploitation would transition privileges and enable broad data manipulation.
OpenCVE Enrichment