Impact
The vulnerability exists in the nVision component of Oracle PeopleSoft Enterprise PeopleTools. An attacker with network access over HTTP can exploit a design flaw that permits unauthorized use of application functionality. The flaw can be leveraged with minimal skill but requires that a non‑attacker user interacts with the system, after which the attacker can gain full control. This establishes unilateral loss of confidentiality, integrity and availability for the entire PeopleSoft instance. The weakness is consistent with improper access control issues that allow elevated user privileges to be abused.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools, versions 8.61 through 8.63, accessed via the PeopleTools nVision module. These are the only versions identified as vulnerable by the vendor. All other released versions are not listed as vulnerable.
Risk and Exploitability
The CVSS vector indicates network accessibility (AV:N), low attack complexity (AC:L), no privileges (PR:N), required user interaction (UI:R), and universal scope (S:U). The CVSS Base Score of 8.8 signals a high severity. The EPSS score of 0.00288 indicates a very low probability of exploitation. The lack of an exemption from the CISA KEV catalog indicates it is not yet known to be actively exploited. The required human interaction from another user introduces a barrier, yet the impact is severe enough that remediation is essential.
OpenCVE Enrichment