Impact
The vulnerability in the Cash Management component of Oracle PeopleSoft Enterprise FIN Cash Management allows an unauthenticated attacker with network access via HTTP to create, delete, or modify critical financial data without providing valid credentials. The flaw enables unauthorized data changes with full confidentiality and integrity implications, potentially leading to a loss of trust in financial records and disruption of business processes.
Affected Systems
Oracle PeopleSoft Enterprise FIN Cash Management version 9.2 is impacted. The issue is confined to this product but may expand to other PeopleSoft applications that interact with the Cash Management component due to a scope change capability.
Risk and Exploitability
The CVSS 3.1 score of 8.7 highlights substantial impact, yet the EPSS estimate of below 1% indicates a low current likelihood of exploitation. The vulnerability is not listed in CISA KEV, meaning no publicly known exploit is documented. Based on the description, the likely attack vector is HTTP requests sent from an unauthenticated host, leveraging a missing authorization check to gain write access to critical data.
OpenCVE Enrichment