Impact
A flaw in the Ren Server component of Oracle PeopleSoft Enterprise PeopleTools permits an unauthenticated user with network access over HTTP to trigger uncontrolled resource consumption. Successful exploitation can cause the application to hang or repeatedly crash, resulting in a complete denial of service. The weakness is identified as CWE‑400 and is quantified by a CVSS v3.1 score of 7.5, indicating a high severity for availability impact.
Affected Systems
The vulnerability affects Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63. The exposed component is the Ren Server service within the PeopleTools application stack.
Risk and Exploitability
The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation is currently unlikely. However, the attack vector is straightforward—unauthenticated HTTP traffic—to which public or internal attackers could potentially access, enabling them to trigger the denial of service. Consequently, the risk to organizations running affected versions remains significant due to the severe impact on availability.
OpenCVE Enrichment