Impact
A flaw in Oracle PeopleSoft Enterprise FIN Staffing Front Office version 9.2 permits an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data without authentication. This access control weakness (CWE‑284) compromises the integrity of all data exposed by the application and could allow the attacker to alter or erase records that are otherwise protected by the system.
Affected Systems
Oracle PeopleSoft Enterprise FIN Staffing Front Office version 9.2 is affected, specifically the Staffing Front Office component.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity, primarily impacting integrity. The EPSS score is under 1%, suggesting a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based over HTTP; no authentication or privileged credentials are needed to exercise the flaw, allowing an attacker to modify data with relative ease.
OpenCVE Enrichment