Impact
This vulnerability resides in the Security component of Oracle PeopleSoft Enterprise PeopleTools and can be exploited by an attacker who already holds low‑privileged local access to the infrastructure where the application runs. By leveraging this weakness, the attacker can create, delete, modify or otherwise manipulate critical data, and gain unauthorized access to that data. The CVSS vector indicates access with high attack complexity, low privilege, no user interaction and a scope change that can affect other products within the same environment. Overall, the impact is a loss of confidentiality and integrity for all accessible data in the affected PeopleSoft installations.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected. No other product versions are listed as impacted in the current advisory.
Risk and Exploitability
The CVSS base score of 7.5 reflects a significant threat, and the EPSS score of 0.00106 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be able to log into the underlying system, meaning the risk is primarily internal. Because the vulnerability allows unauthorized data modification and access, internal attackers could achieve further lateral movement or impact other systems that rely on PeopleSoft data. While external exploitation appears unlikely without a prior compromise, the potential for internal damage is high and should be treated as such. Prompt mitigation through patching is recommended to eliminate this risk.
OpenCVE Enrichment