Impact
The flaw exists in the Global Payroll for Switzerland component of Oracle PeopleSoft Enterprise HCM and is a permissions-related access control weakness (CWE-284). A high-privileged attacker who can reach the application over HTTP can exploit the vulnerability to achieve full control of the affected system, resulting in loss of confidentiality, integrity and availability.
Affected Systems
Oracle PeopleSoft Enterprise HCM Global Payroll Switzerland version 9.2 is impacted.
Risk and Exploitability
The CVSS v3.1 base score of 9.1 places the flaw in the critical range, and the attack requires only network access over HTTP. The EPSS score of less than 1% indicates that active exploitation is currently rare, and the flaw is not listed in CISA's KEV catalog. Nevertheless, because the attack vector is network-based and the impact is total system takeover, the risk remains high for affected deployments.
OpenCVE Enrichment