Impact
A local vulnerability exists in the Tuxedo component of Oracle PeopleSoft Enterprise PeopleTools that specifically targets versions 8.61 through 8.63. The flaw permits an attacker who has logged into the host infrastructure with a low‑privileged account to compromise the PeopleSoft application. Successful exploitation results in full control of PeopleSoft Enterprise PeopleTools and consequently a serious confidentiality, integrity, and availability impact as described by the CVSS 3.1 base score of 7.0.
Affected Systems
Oracle Corporation PeopleSoft Enterprise PeopleTools versions 8.61, 8.62, and 8.63 are affected.
Risk and Exploitability
The vulnerability requires local access and a low‑privileged account, making exploitation more difficult than remote attacks but still feasible for a host user. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV, indicating no known public exploitation at this time. The CVSS vector (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms the medium‑high severity as well as comprehensive impact if the flaw is exploited.
OpenCVE Enrichment