Impact
The flaw resides in the Configuration Manager component of PeopleSoft Enterprise PeopleTools. A low‑privileged attacker with network access can inject arbitrary SQL through the exposed interface and load the application with crafted payloads. Successful exploitation grants the attacker full control over the application, bypassing all business logic and data‑access checks, and results in a complete compromise of the affected environment, impacting confidentiality, integrity, and availability of the stored data. This vulnerability is classified as a SQL injection and relates to improper or missing access control (CWE‑284) and authentication bypass (CWE‑306).
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61, 8.62, and 8.63 are vulnerable. The flaw is located in the Configuration Manager component. No other modules are indicated as affected in the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 signifies a high‑threat level. Attackers need only network reach and low attack complexity, with credentials of low privilege. The EPSS score of < 1% indicates the probability of exploitation is currently low, yet the high impact score warrants attention. The vulnerability is not yet listed in the CISA KEV catalog but the exposure on the public network and the severe impact make it a priority for mitigation.
OpenCVE Enrichment