Impact
A vulnerability in PeopleSoft Enterprise FIN Cash Management version 9.2 allows an attacker with basic logon access to the underlying infrastructure to compromise the application. The flaw can be exploited easily at a local level and results in full takeover of the application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle PeopleSoft Enterprise FIN Cash Management version 9.2 is the primary affected product; the scope change flag indicates that successful exploitation could also impact other integrated products and components.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score of less than 1% suggests that widespread exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local or low‑privileged access to the system hosting PeopleSoft; once compromised, the attacker can affect other integrated products as the vulnerability’s scope changes.
OpenCVE Enrichment