Impact
A vulnerability exists in Oracle PeopleSoft Enterprise PeopleTools (Business Interlink component) that can be exploited by an attacker with low privileges who can reach the system via HTTP. The flaw permits unauthorized access to critical data and provides the ability to insert, modify, or delete accessible data, thereby compromising confidentiality and partially affecting integrity.
Affected Systems
Oracle Corporation PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. The vulnerability is specific to the Business Interlink component and may also impact other Oracle PeopleSoft products when properly configured.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 8.5 and an EPSS score of less than 1%, indicating a high severity but a low probability of exploitation. It is not listed in the CISA KEV catalog. The attack vector is inferred to be network-based over HTTP, with low attack complexity and low privileges required, suggesting that a compromised or exploited system could be leveraged for broader attacks on PeopleSoft data. The CVSS vector indicates a high confidentiality impact and low integrity impact, with a changed scope due to potential cross-product effects.
OpenCVE Enrichment