Impact
The flaw resides in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools, allowing an unauthenticated attacker with network access to HTTP to compromise the system. The vulnerability involves improper authorization (CWE-284) and missing authentication (CWE-306), enabling an attacker to subvert confidentiality, integrity, and availability, effectively granting full control of the installation. According to the reported CVSS v3.1 base score of 8.1, the impact is high.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. The Integration Broker module is exposed to unauthenticated HTTP traffic, creating a direct attack surface for take‑over.
Risk and Exploitability
The attacker only needs connectivity to the HTTP port of the Integration Broker; no credentials or UI interaction are required. The base score of 8.1 reflects a severe threat, while the EPSS score indicates a very low (but non‑zero) exploitation probability of less than 1 %. This vulnerability is not listed in the CISA KEV catalog. The attack vector is a network‑based intrusion exploiting the lack of proper authentication and access controls on the Integration Broker service.
OpenCVE Enrichment