Impact
A vulnerability in Oracle PeopleSoft Enterprise FIN Project Costing allows an attacker with low privileges and network access via HTTP to read critical data that should be restricted. Successful exploitation results in a confidentiality breach where the attacker can retrieve or view all data available in the PeopleSoft environment.
Affected Systems
This issue affects Oracle Corporation's PeopleSoft Enterprise FIN Project Costing version 9.2. The affected product is part of the Oracle PeopleSoft suite.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate severity, primarily impacting confidentiality. The EPSS score is not available, but the description states the vulnerability is easily exploitable over an HTTP connection from the network. This attack does not require user interaction and relies on a low privilege attacker, making it a viable threat. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment