Impact
The vulnerability lies in the Configuration Manager component of Oracle PeopleSoft Enterprise PeopleTools. It enables a low‑privileged attacker with network access to inject and execute arbitrary SQL commands. If successfully exploited, the attacker can gain full control over the PeopleSoft application, compromising confidentiality, integrity, and availability of organizational data.
Affected Systems
Affected systems are Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The flaw is limited to the Configuration Manager function within these releases.
Risk and Exploitability
The CVSS score of 8.8 indicates a severe impact. The vector shows a network access requirement, low attack complexity, and low privileges required. EPSS is not listed, so exploitation probability remains unknown, but the high score signals a real threat. The vulnerability is not yet catalogued in CISA KEV, suggesting no known widespread exploits, yet the potential for rapid compromise warrants immediate attention.
OpenCVE Enrichment