Impact
PeopleSoft Enterprise CC Common Application Objects in Oracle PeopleSoft contains an improper access control flaw (CWE‑284 and CWE‑601) that allows a low‑privileged attacker with network access over HTTP to create, delete, or modify critical data. The flaw requires the attacker to obtain limited privileges and a secondary user’s interaction, so it is not a fully remote exploit. Once exploited, the attacker can gain unauthorized read/write access to all data handled by the application, compromising confidentiality and integrity.
Affected Systems
Oracle Corporation – PeopleSoft Enterprise CC Common Application Objects version 9.2 is impacted. The CNA lists only this product version; no other versions are reported as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.7 indicates high severity with substantial confidentiality and integrity impacts. The EPSS score is less than 1%, suggesting exploitation is unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw from any remote host with HTTP access, but they need a low‑privileged account and require a human interaction from another user. Successful exploitation could allow the attacker to create, delete, or modify critical data and gain full access to all data accessible through the application.
OpenCVE Enrichment