Impact
The vulnerability is a CWE‑284 Improper Access Control flaw that permits unauthenticated attackers to access and manipulate confidential information via the HTTP interface of Oracle PeopleSoft Enterprise HCM Human Resources 9.2. An attacker can read critical data and perform unauthorized updates, inserts, or deletes on accessible data. The flaw leads to significant confidentiality loss and potential integrity compromise while availability is unaffected.
Affected Systems
The affected system is Oracle PeopleSoft Enterprise HCM Human Resources 9.2, specifically the French Public Sector Specific component; no other product versions are listed as affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 reflects the high impact on confidentiality and lower impact on integrity. The EPSS score of less than 1 % indicates that, while the vulnerability is easily exploitable, the likelihood of real‑world exploitation at present is low and it is not listed in the CISA KEV catalog. The attack requires only network access to the HTTP endpoint and no authentication, making it simple for an attacker to target the system if it is reachable from the internet or an untrusted network.
OpenCVE Enrichment