Impact
The vulnerability permits an attacker who already has high privileged local logon to the infrastructure hosting Oracle PeopleSoft Enterprise FIN eSettlements to read a subset of the application data, thereby compromising confidentiality. It is a CWE‑306 flaw and a low‑severity issue but results in information leakage to a privileged attacker.
Affected Systems
Oracle PeopleSoft Enterprise FIN eSettlements version 9.2, deployed on enterprise infrastructure; the affected component is eSettlements.
Risk and Exploitability
With a CVSS base score of 2.3 and an EPSS score of less than 1%, the risk of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. An attacker must already possess local high‑privilege access; no network or user‑interaction vector is required. The flaw can lead to unauthorized read access to a subset of sensitive data, limited to confidentiality impact only.
OpenCVE Enrichment