Impact
A vulnerability in the SQR component of Oracle PeopleSoft Enterprise PeopleTools allows a low‑privileged user who has logged into the underlying infrastructure to compromise the application. Successful exploitation PeopleTools and consequently exposes all data and services controlled by the system, affecting confidentiality, integrity and availability. The weakness permits the attacker to bypass normal security controls and gain full operational control of the application environment.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise PeopleTools in versions 8.61 through 8.63 are affected. The flaw resides in the SQR component of PeopleSoft.
Risk and Exploitability
The CVSS 3.1 base score is 7.8, indicating a high‑severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation at this time, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Attack requires the attacker to already have a logged‑on session on the infrastructure where PeopleSoft executes, implying a local attack vector and low complexity. to compromise the application.
OpenCVE Enrichment