Impact
PeopleSoft Enterprise PeopleTools (component SQR) is vulnerable to a flaw that allows a high privileged attacker with local access to take over the application. The vulnerability requires the attacker to log on to the infrastructure where PeopleSoft runs and to enlist a separate user for interaction, making exploitation difficult. If compromised, the attacker can exercise full control over PeopleSoft Enterprise PeopleTools and may affect other connected products because the flaw includes a scope change.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates moderate to high severity, with local attack, high privilege, required user interaction, and scope change. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Externally, a local privileged user with access to the infrastructure and the cooperation of another user is required to successfully exploit this vulnerability.
OpenCVE Enrichment