Impact
The flaw exists in the FM Need Analysis Calculator component of Oracle PeopleSoft Enterprise CS Financial Aid and permits a local attacker with low privileges to compromise the application. When successfully attacked, the vulnerability can lead to unauthorized access to critical data or complete access to all data handled by the application, impacting confidentiality solely.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise CS Financial Aid version 9.2.38 is affected. The vulnerability is limited to this specific release of the Financial Aid component.
Risk and Exploitability
The CVSS 3.1 base score of 5.5 reflects moderate severity, with local access, low privileges, no user interaction, and a single impact on confidentiality. The EPSS score is below 1 %, indicating a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must already have local, low‑privileged access to the infrastructure running PeopleSoft; they can then manipulate the component to read protected data. Once the component is abused, the attacker effectively bypasses the application’s authorization controls for sensitive information.
OpenCVE Enrichment