Impact
This vulnerability in Oracle PeopleSoft Enterprise FIN General Ledger Argentina stems from insufficient authorization checks in the General Ledger module. A low‑privilege attacker who can reach the application over HTTP can craft requests that bypass normal role restrictions, enabling unauthorized creation, deletion, or modification of critical ledger records. The flaw also permits a partial denial of service by rendering the application unresponsive to legitimate users. Because confidentiality is not affected, the primary impacts are on data integrity and availability, undermining accounting processes and regulatory compliance.
Affected Systems
This issue affects Oracle PeopleSoft Enterprise FIN General Ledger Argentina version 9.1, specifically the General Ledger component exposed through the HTTP interface. Any installation that hosts the General Ledger portal over HTTP and runs the 9.1 release is vulnerable. The advisory lists only version 9.1 as affected; later releases may contain fixes but are not known to be impacted.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity, with high integrity and low availability impact. The EPSS score of < 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not included in CISA’s KEV catalog. Nonetheless, the attack vector is network (HTTP), requiring only low user privileges and no user interaction. If exploited, the attacker can damage ledger accuracy and impede business operations, but no known exploits have been publicly documented.
OpenCVE Enrichment