Impact
A flaw in the Business Interlink component of Oracle PeopleSoft Enterprise PeopleTools permits an attacker to send specially crafted HTTP requests without authentication, resulting in a complete takeover of the application. This compromise can expose sensitive data, modify system state, and disrupt service availability. The weakness is an Access Control flaw, identified as CWE-284.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 contain the vulnerable Business Interlink component. No other product versions or components are reported to be affected in the current advisory.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.1 marks this vulnerability as high severity. The EPSS score is below 1 %, indicating a low likelihood of current exploitation, and the issue is not included in the CISA KEV catalog. Nonetheless, the attack can be performed over HTTP by an unauthenticated adversary, making the path essentially open to any attacker with network visibility.
OpenCVE Enrichment