Impact
A flaw in Oracle PeopleSoft Enterprise CS Campus Community 9.2.38 allows an unauthenticated attacker who can reach the physical communications segment attached to the hardware where the application runs to compromise the system. Successful exploitation grants the attacker unauthorized access to critical data or, in the worst case, to all data accessible by the application, and the attacker can also insert, update or delete data. The weakness is an access control violation that leads to a high confidentiality impact and a low integrity impact as reflected in the CVSS vector.
Affected Systems
Oracle PeopleSoft Enterprise CS Campus Community 9.2.38 is the affected product. No other versions or vendor products are listed as affected.
Risk and Exploitability
The CVSS v3.1 base score is 5.9, indicating a moderate severity. The EPSS score is less than 1%, suggesting a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is adjacent network, requiring physical proximity or network access to the server’s communication segment, and the exploit does not require user interface interaction or elevated privileges.
OpenCVE Enrichment