Impact
An unauthenticated attacker who has local access to the infrastructure hosting PeopleSoft Enterprise FIN Project Costing can compromise the application. The vulnerability requires the attacker to persuade a user to interact with the system, after which the attacker can take over the application, resulting in total loss of confidentiality, integrity, and availability. This attack demonstrates a high-risk local compromise path that can be leveraged if the ad‑hoc environment is not well protected.
Affected Systems
Oracle’s PeopleSoft Enterprise FIN Project Costing, version 9.2, is the only product and version affected by this vulnerability. The weakness exists in the Projects component and applies to installations that run this version within an unprotected local environment.
Risk and Exploitability
The vulnerability carries a CVSS v3.1 base score of 7.8, indicating a medium‑to‑high severity outcome. The EPSS score is below 1 %, reflecting a very low but non‑zero probability of exploitation at the present time, and the issue is not listed in CISA’s KEV catalog. Exploitation requires local access and a user interaction step; no special privileges are needed on the target system. Based on these metrics the risk is considered moderate, but the potential impact warrants immediate attention.
OpenCVE Enrichment