Impact
The flaw resides in the PeopleSoft Enterprise PeopleTools component SQR and allows a low-privileged, networked attacker to execute commands via HTTP. The vulnerability can lead to unauthorized access to all data that the web application can reach and can also trigger a complete denial of service by causing the application to hang or crash repeatedly. It is represented by CVSS 3.1 base score 8.1 with high impact to confidentiality and availability.
Affected Systems
Oracle PeopleSoft Enterprise PeopleTools versions 8.61 through 8.63 are affected. These are the systems that contain the vulnerable SQR component.
Risk and Exploitability
The attack vector is inferred to be external over HTTP, requiring only low privileges but network access. The EPSS score of less than 1 % indicates a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, its high CVSS score and the possibility of full data exfiltration or service disruption mean that an organization using this product should consider the risk high if not mitigated.
OpenCVE Enrichment