Impact
A flaw in the Charting component of Oracle PeopleSoft Enterprise PeopleTools allows a low‑privileged attacker with network access via HTTP to compromise the application. Successful exploitation would enable the attacker to create, delete, or modify critical data and gain unauthorized access to all PeopleSoft data accessible to the compromised account. The weakness is an access control issue (CWE‑284).
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools, version 8.61 through 8.63, specifically the Charting component. These versions are the ones affected by the vulnerability.
Risk and Exploitability
The CVSS v3.1 base score is 7.3, indicating a high severity level with confidentiality and integrity impact. The EPSS score is below 1%, showing a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker with low privileges and user interaction from a person other than the attacker, implying it may rely on social engineering or credential misuse. Given these conditions, the risk is moderate to high if the environment is exposed to the public Internet, but the attack surface is limited due to the necessary human component.
OpenCVE Enrichment