Impact
A flaw in the security component of Oracle PeopleSoft Enterprise FIN Common Objects allows a low‑privileged local attacker to compromise data integrity by creating, deleting, or modifying critical records. The weakness is an instance of unauthorized privilege escalation, improper authorization, and incorrect permissions, and it requires the attacker to have a low‑privileged account with local access and to prompt another user to execute actions. Successful exploitation compromises integrity without directly affecting confidentiality or availability.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects version 9.2 is the only documented affected release. No other versions or product lines are referenced in the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 4.4 indicates a moderate integrity impact. The EPSS score of less than 1 % reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring a low‑privileged account and human interaction from another user. The practical risk is therefore limited to insider or social‑engineering scenarios, but a successful attack would allow unauthorized data modification.
OpenCVE Enrichment