Impact
Vulnerability in the Integration Broker component of Oracle PeopleSoft Enterprise PeopleTools, identified as CWE-284, allows a low-privileged attacker with network access via HTTP to create, delete, or modify critical data, thereby compromising data integrity and potentially enabling unauthorized creation, deletion, or alteration of all PeopleSoft accessible data.
Affected Systems
Affects Oracle PeopleSoft Enterprise PeopleTools, specifically the Integration Broker component, for versions 8.61 through 8.63.
Risk and Exploitability
The flaw can be exploited remotely using an HTTP connection; its CVSS 3.1 score of 7.7 indicates a high severity for data integrity. The EPSS score is below 1%, suggesting that exploitation is currently unlikely, and it is not listed in the CISA KEV catalog. Nevertheless, because the vulnerability is triggered through a web interface, administrators should restrict external access or apply the vendor patch promptly to mitigate the risk of integrity compromise.
OpenCVE Enrichment