Impact
An unauthenticated network attacker can exploit a flaw in the Core component of Oracle PeopleSoft Enterprise HCM Human Resources to create, delete, or modify critical database records and to cause frequent application crashes. The vulnerability is an instance of Improper Access Control that bypasses authentication, thereby compromising data integrity and disrupting application availability. The CVE description does not explicitly classify the flaw as Improper Access Control; this classification is inferred from the described behavior.
Affected Systems
Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 is affected. All installations of this version that are reachable via TCP network traffic are vulnerable, regardless of deployment model.
Risk and Exploitability
The CVSS v3.1 score of 7.4 indicates high impact on integrity and availability. The EPSS score of less than 1% reflects a low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The description explicitly states that an unauthenticated attacker with TCP network access can exploit the flaw; no credentials are required beyond network connectivity to the affected service.
OpenCVE Enrichment