Impact
Vulnerability in the PeopleSoft Enterprise PeopleTools Panel Processor allows an attacker with network access to HTTP, low privileged credentials and some human interaction from a third party to update, insert or delete limited data and read a subset of data. The flaw is an access‑control weakness influencing confidentiality and integrity but not availability, as reflected in the CVSS vector.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. The issue is confined to the Panel Processor component but the impact may propagate to other integrated products due to scope changes.
Risk and Exploitability
The CVSS base score of 4.4 indicates moderate risk. Exploitation requires both low‑privileged credentials and a user action from someone other than the attacker, making the attack scenario uncommon and less likely to be automated. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. Nevertheless, the potential for unauthorized data modification warrants prompt remediation.
OpenCVE Enrichment