Impact
The vulnerability in the Install and Packaging component of Oracle PeopleSoft Enterprise PeopleTools permits an unauthenticated attacker who can reach the system over HTTP to create, delete, or modify critical data, effectively compromising the confidentiality and integrity of all accessible PeopleSoft data. The likely attack vector is network access through the HTTP protocol, exploiting a weakness that bypasses authentication mechanisms required for these operations.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools, specifically versions 8.61 through 8.63, are susceptible. No other products or versions are indicated as affected in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 reflects a high risk to confidentiality and integrity with high attack complexity and no privileges or user interaction required. The EPSS score indicates lower than 1% probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it may not be currently actively exploited but remains a significant risk. An attacker who successfully exploits this flaw can gain unauthorized access to or tampering of critical organizational data without needing to authenticate or interact with the system directly.
OpenCVE Enrichment