Impact
This vulnerability, identified as CWE-284, resides in the Cube Manager component of Oracle PeopleSoft Enterprise PeopleTools. An attacker who has logged on locally to the infrastructure where PeopleSoft runs can exploit the flaw with high complexity and low privilege requirements. Successful exploitation leads to complete takeover of the PeopleSoft application, resulting in severe breaches of confidentiality, integrity and availability.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools is affected. The vulnerable product versions are 8.61 through 8.63, inclusive.
Risk and Exploitability
The CVSS v3.1 Base Score is 7.0 with a local attack vector, high attack complexity, low privileges, no user interaction, and impacts all core security dimensions. Despite a low EPSS of less than 1% and absence from the CISA KEV catalog, the potential for a full compromise exists for any organization that allows local users to access the PeopleSoft infrastructure. The reliance on local infrastructure credentials means the risk is confined to users with physical or network access to the application servers.
OpenCVE Enrichment