Impact
This vulnerability enables a highly privileged attacker who can reach the application over HTTP to fully compromise the PeopleSoft Enterprise FIN Billing Argentina system. The flaw is an access control weakness (CWE‑284) and the CVSS 3.1 Base Score of 7.2 reflects significant confidentiality, integrity and availability impacts.
Affected Systems
Oracle’s PeopleSoft Enterprise FIN Billing Argentina, version 9.1 is affected.
Risk and Exploitability
The vulnerability is classified as high severity with a CVSS score of 7.2. The EPSS score is <1%, indicating a low current exploitation probability and the flaw is not listed in CISA’s KEV catalog. The vector is an HTTP request sent over the network to the vulnerable component. A privileged attacker that gains network access can leverage the flaw to gain control of the system.
OpenCVE Enrichment