Impact
The vulnerability in Oracle PeopleSoft In-Memory Project Discovery version 9.2 can be exploited by a low‑privileged attacker who has network access via HTTP. The flaw permits bypassing privilege checks and effectively taking control of the affected service, corresponding to CWE‑269: Improper Privilege Management. Successful exploitation results in full compromise of confidentiality, integrity, and availability for that instance. Because the vulnerability’s scope changes, the impact extends beyond the In‑Memory Project Discovery component and may affect additional PeopleSoft products as well.
Affected Systems
Oracle PeopleSoft In-Memory Project Discovery version 9.2, part of Oracle PeopleSoft. Although the vulnerability is specific to that component, the scope change indicates that other PeopleSoft products may also be impacted by exploitation.
Risk and Exploitability
The CVSS v3.1 base score of 9.9 indicates a critical severity level. The EPSS score of less than 1 % suggests that, as of the latest data, exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploit has been reported. Attackers can reach the vulnerable component via standard HTTP requests, requiring only a low‑privileged account. The scope change means that exploitation could affect more than the targeted component, potentially impacting other PeopleSoft products. The combination of remote access, low attack effort, and this expanded impact makes the flaw a high‑priority risk.
OpenCVE Enrichment