Impact
Vulnerability in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw can be exploited easily, giving the attacker full control over the system. Successful exploitation results in a complete takeover, with confidentiality, integrity, and availability fully compromised, as reflected in the CVSS 3.1 Base Score of 9.8.
Affected Systems
This issue affects Oracle Corporation's PeopleSoft Enterprise PeopleTools, specifically versions 8.61 through 8.63. The vulnerability is present in the Business Interlink component. Systems running these versions are at risk if the component is exposed to external or untrusted networks.
Risk and Exploitability
The CVSS score of 9.8 denotes critical severity, and the absence of an EPSS score indicates no current data on exploitation frequency, however the vulnerability remains high risk due to its remote nature and lack of authentication requirement. The exploitation pathway is straightforward: an attacker sends crafted HTTP requests to the vulnerable endpoint, bypassing authentication and executing code. Because the flaw is unauthenticated and no mitigations are in place, the risk is immediate for exposed systems. Oracle does not list this vulnerability in the CISA KEV catalog, but the critical score warrants urgent remediation.
OpenCVE Enrichment