Impact
A vulnerability in Oracle PeopleSoft Enterprise FIN Engineering Argentina 9.1 allows a high‑privileged attacker with network access via HTTP to perform unauthorized update, insert or delete operations, as well as read sensitive data. The flaw is an improper access control weakness (CWE‑284) that compromises the integrity and confidentiality of the application’s data.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise FIN Engineering Argentina version 9.1 is affected by this issue.
Risk and Exploitability
The CVSS score of 3.3 indicates a low to moderate risk level, and the EPSS score of less than 1% suggests that this vulnerability is unlikely to be actively exploited. However, because it requires a high‑privileged attacker who can reach the system over HTTP and permits data modification and disclosure, it remains a concern for organizations that operate the affected PeopleSoft instance.
OpenCVE Enrichment