Impact
This vulnerability exists in Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 within the Security component. A low‑privileged attacker with network access over Oracle Net can exploit the flaw to create, delete or modify data and ultimately gain full access to all PeopleSoft Human Resources data. The impact includes confidentiality and integrity damage.
Affected Systems
Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 is affected. No other versions or products are listed.
Risk and Exploitability
The CVSS base score of 6.8 indicates moderate to high risk. The EPSS score of less than 1 % suggests exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attackers are expected to use a network vector via Oracle Net, requiring a low‑privileged account but no user interaction.
OpenCVE Enrichment