Impact
A flaw in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools enables an attacker with low privileges over HTTP to create, delete, modify critical data, or trigger frequent crashes of the application. The vulnerability undermines integrity and availability, allowing unauthorized data manipulation and denial‑of‑service attacks, but does not affect confidentiality.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools, versions 8.61 through 8.63, are affected.
Risk and Exploitability
With a CVSS v3.1 base score of 8.1, this issue is rated high severity. The EPSS score of less than 1 % indicates a low overall exploitation probability in the wild, and it is not listed in the CISA KEVitable; an attacker who can reach the application over the network via HTTP can leverage it without needing elevated privileges or complex prerequisites.
OpenCVE Enrichment