Impact
Oracle PeopleSoft Enterprise PeopleTools is vulnerable due to an issue in the PIA Core Technology component that allows an unauthenticated attacker with network access via HTTP to compromise the system. Successful exploitation can lead to full takeover of the PeopleSoft instance, causing loss of confidentiality, integrity and availability. The vulnerability is classified with a CVSS 3.1 base score of 8.1, indicating a high‑severity flaw.
Affected Systems
The affected product is Oracle PeopleSoft Enterprise PeopleTools, specifically versions 8.61 through 8.63. The vulnerability was found in the PIA Core Technology component of these releases.
Risk and Exploitability
The CVSS vector indicates an authenticated‑null penalty, no user interaction, and a single impact scope, meaning remote attackers can gain full control without credentials. No EPSS score is currently available, and the vulnerability is not listed in the CISA KEV catalog. Despite the lack of EPSS data, the high CVSS score and remote nature of the flaw raise the likelihood of exploitation.
OpenCVE Enrichment