Impact
Oracle PeopleSoft Enterprise PeopleTools includes a flaw in its PeopleCode component that can be triggered from an external HTTP request. When accessed by an attacker with high privileges on the network, the vulnerability allows arbitrary execution of PeopleCode, enabling the attacker to gain full control over the application, which includes the ability to read, modify or delete data and to alter application behavior. The impact covers confidentiality, integrity and availability, giving a potential attacker a complete takeover of the installed instance. The flaw is a CWE-284 (Missing Authorization) and CWE-306 (Missing Authentication) vulnerability.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools product, with affected releases 8.61 through 8.63, is exposed to the flaw. Users running any of these specific builds are at risk.
Risk and Exploitability
The CVSS v3.1 base score of 7.2 places this issue in the high severity range. The EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, but it is nonetheless a published vulnerability. The flaw is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint via standard HTTP traffic over the network; the vector requires the attacker to have high privileges in order to successfully deliver the exploit. The vulnerability does not depend on user interaction and can be fully automated once the attacker has network access.
OpenCVE Enrichment