Impact
An unauthenticated network attacker can exploit a vulnerability in the Core component of Oracle PeopleSoft Enterprise HCM Human Resources to create, delete, or modify critical data and to cause frequent application crashes. The flaw, classified as Improper Access Control, enables the attacker to bypass authentication and gain full control over database records, compromising data integrity and disrupting application availability.
Affected Systems
Oracle PeopleSoft Enterprise HCM Human Resources version 9.2 is affected. All installations of this version that are reachable via TCP network traffic are vulnerable, regardless of deployment model.
Risk and Exploitability
The CVSS v3.1 score of 7.4 reflects a high impact on integrity and availability. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote, unauthenticated TCP connection to the affected service; the attacker does not require credentials but must reach the application over the network to abuse the flaw.
OpenCVE Enrichment