Impact
Vulnerability in the PeopleSoft Enterprise PeopleTools Panel Processor permits an attacker with network access via HTTP and low‑privileged credentials, combined with a user action from a third party, to perform unauthorized updates, insertions, or deletions on restricted data and read a limited subset of data. This flaw arises from inadequate access controls, affecting confidentiality and integrity but not availability.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. The issue is confined to the Panel Processor component but the impact may propagate to other integrated products due to scope changes.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate risk. Exploitation requires both low‑privileged credentials and a user action from someone other than the attacker, making the attack scenario uncommon and less likely to be automated. EPSS score is less than 1 percent, indicating a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the potential for unauthorized data modification warrants prompt remediation.
OpenCVE Enrichment