Impact
An easily exploitable vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows an attacker who can reach the system via HTTP to achieve high privileged compromise and takeover of the application. The flaw provides full control over confidentiality, integrity, and availability, resulting in a complete loss of the application’s security posture.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools product, specifically versions 8.61 through 8.63, is affected. Users running these releases are exposed to the risk.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 places this issue in the high severity range. With no EPSS data available and no listing in CISA KEV, the likelihood of current exploitation is uncertain, but the potential impact is severe. The attack vector is inferred to be remote over the network via HTTP, requiring an attacker with high privileges to execute the exploit.
OpenCVE Enrichment