Impact
The vulnerability lies in the Research Tracking component of Oracle PeopleSoft Enterprise CS Student Records. An unauthenticated attacker with network access over HTTP can exploit this weakness and read a restricted subset of data that should not be publicly accessible. The primary impact is a confidentiality breach, allowing information that the attacker should not be able to obtain to be disclosed. The weakness represents a lack of proper access control, where the application fails to enforce authorization policies for unauthenticated requests.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise CS Student Records version 9.2.38 is affected. The vulnerability is specific to the Research Tracking module within this product.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity, with impacts limited to confidentiality. The EPSS score of less than 1% suggests that, at present, the probability of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog, and no public exploit code has been reported. The likely attack vector is a simple unauthenticated HTTP request to a publicly exposed endpoint of the Research Tracking component, requiring no credentials or privileged access.
OpenCVE Enrichment