Impact
A vulnerability exists in Oracle PeopleSoft Enterprise CS Financial Aid that allows an attacker with low privileges who has logged into the underlying infrastructure to create, delete, or modify critical data. The flaw results in confidentiality and integrity impacts, with the CVSS 3.1 vector indicating a local attack versus local access privileges and no user interaction. The weakness corresponds to improper authorization, permitting unauthorized changes to system data.
Affected Systems
Oracle peopleSoft Enterprise CS Financial Aid, version 9.2.38, is affected.
Risk and Exploitability
The CVSS base score of 6.1 signals moderate severity, while an EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV registry. Attacks would require an attacker to have already gained local access to the infrastructure running PeopleSoft, making the risk contingent on the security of the operating environment but still significant enough to warrant remediation.
OpenCVE Enrichment