Impact
The vulnerability in PeopleSoft Enterprise CC Common Application Objects allows an unauthenticated attacker to compromise the system. Upon successful exploitation the attacker can take full control of the application, potentially affecting all data confidentiality, integrity, and availability. The flaw is a result of improper authentication and access control weaknesses. The CVSS vector indicates that no user interaction or privileges are required and the impact covers confidentiality, integrity, and availability.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise CC Common Application Objects, version 9.2.
Risk and Exploitability
The CVSS base score of 8.1 signifies a high severity. The EPSS score of < 1% indicates a very low probability of exploitation in the current data set, but the fact that it can be reached over the network via Oracle Net and requires no authentication makes it a serious threat. The vulnerability is not listed in the CISA KEV catalog, yet the potential for enterprise‑wide compromise warrants immediate attention.
OpenCVE Enrichment