Impact
This vulnerability in PeopleSoft Enterprise CRM Common Objects allows an unauthenticated attacker with network access over HTTP to take full control of the application, resulting in confidentiality, integrity, and availability compromise. The weakness is a failure in authorization and privilege handling as indicated by the Scope Change in the CVSS vector, which enables system takeover. The impact is a complete loss of the affected instance for the adversary.
Affected Systems
Oracle Corporation PeopleSoft Enterprise CRM Common Objects, version 9.2.23. The advisory applies specifically to this product version; no other versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.0 classifies this as Critical, with a high impact on all three security objectives. The EPSS score of <1% suggests low overall exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. However, the vulnerability may be leveraged remotely over an open HTTP interface without authentication, making it potentially attractive to attackers that can reach the network. The Scope Change in the CVSS vector indicates that successful exploitation could extend to additional PeopleSoft products beyond the Common Objects component. The weakness permits privilege escalation and full takeover of the application environment.
OpenCVE Enrichment