Impact
The vulnerability resides in the Job Opening component of Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager version 9.2. An attacker who is only logged in with low privileges and has network access through HTTP can exploit this flaw. The flaw is easily exploitable and, if successful, allows the attacker to compromise the entire application, abolishing confidentiality, integrity and availability. The CVSS vector lists an Attack Vector of Network, Authentication required is low, and the scope is of a low‑privileged user can lead to full takeover of the system.
Affected Systems
The affected vendor is Oracle Corporation, product PeopleSoft Enterprise HCM Talent Acquisition Manager. The only explicitly impacted release is version 9.2. No other products or versions are mentioned; however, the description states that the issue may have a broader scope that could affect additional PeopleSoft products.
Risk and Exploitability
The CVSS base score is 9.9, the maximum severity. The EPSS score indicates a very low current exploitation probability (< 1 %), and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, because the attack can be initiated from a network node using HTTP the risk of compromise remains high once the flaw exists. If left unpatched, an adversary could gain unrestricted access to the application, enabling data exfiltration, modification, and denial of service.
OpenCVE Enrichment