Impact
PeopleSoft Enterprise FIN Grants 9.2 contains an access control flaw that allows an unauthenticated attacker who can reach the application over HTTP to modify, insert, or delete data and read a subset of the system's data. This vulnerability provides confidentiality and integrity impacts as reflected by the CVSS 4.8 rating. The weakness is rooted in improper access control (CWE‑284).
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise FIN Grants, version 9.2, is the affected product. The vulnerability is present in the Grants component of that release.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate potential impact, and the EPSS score of less than 1 % shows that this vulnerability is not currently widely exploited. It is not listed in the CISA KEV catalog. An attacker can reach the vulnerable interface directly over HTTP without authentication, satisfying the network attack vector. No prior authentication, privileged access, or user interaction is required, allowing the attacker to modify or read data.
OpenCVE Enrichment