Impact
The vulnerability resides in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft, specifically in version 9.1. The flaw allows a low‑privileged attacker with network access over HTTP to gain unauthorized access to the hub. This can result in disclosure of critical data or complete access to all data exposed by the hub. The weakness is a privilege escalation that can affect the confidentiality of the data while not impacting integrity or availability directly.
Affected Systems
Affected systems are Oracle PeopleSoft Enterprise PRTL Interaction Hub running version 9.1. The advisory notes that a scope change could allow attacks to impact additional related products that connect to the hub.
Risk and Exploitability
The CVSS score of 7.7 indicates a high‑severity vulnerability that requires network access and low attacker effort. The EPSS score is less than 1%, suggesting that widespread exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit operates over HTTP, it is likely to be discovered during routine web‑port scanning, making it a readily available attack vector for low‑privileged adversaries.
OpenCVE Enrichment