Impact
A local low‑privileged attacker who can log on to the infrastructure that runs PeopleSoft Enterprise FIN Pay/Bill Management can exploit an unprotected function in Paybill Management. The flaw allows the attacker to read critical data, potentially obtaining all information exposed by the PeopleSoft application, without affecting integrity or availability. The vulnerability is described as "Easily exploitable vulnerability" that results in unauthorized access to data and is mapped to a CVSS 3.1 score of 5.5 with a high confidentiality impact. This is a privilege escalation flaw (CWE‑306) caused by lack of authentication.
Affected Systems
Oracle PeopleSoft Enterprise FIN Pay/BillManagement version 9.2 is affected. No other product versions or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 5.5 places the flaw in the medium‑severity range, but the EPSS score of less than 1 % indicates current exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or internal, requiring a user to have logon access to the host that hosts the PeopleSoft instance. Once logged on, the attacker can gain read‑only access to all sensitive financial data managed by PeopleSoft Pay/Bill Management.
OpenCVE Enrichment