CVE-2026-61104
LOW
3.7
CVSS 3.1
Metadata
Severity & Metrics
3.7
LOW CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Oracle Corporation | PeopleSoft Enterprise CS Student Records | — | 9.2.38 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Records. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Student Records accessible data. |
| CWE-200 | adp | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 3.7 | LOW | 3.1 | cna | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
References (1)
- Oracle Advisory https://www.oracle.com/security-alerts/cpujul2026.html