Impact
A vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product allows an attacker with low privileges and network access over HTTP. Based on the description, it is inferred that the vulnerability can be exploited as an authentication bypass. This flaw can lead to a complete takeover of the application, affecting confidentiality, integrity, and availability. The defect is categorized as CWE-284, indicating improper access control.
Affected Systems
Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil version 9.1, specifically the Staffing component. No other versions or related products are listed as affected according to the advisory.
Risk and Exploitability
The CVSS score of 9.9 places the issue in the critical category, meaning a successful exploit could provide remote code execution or full application takeover. The EPSS score of < 1 % suggests that the likelihood of exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network HTTP access, where an attacker can send crafted requests to trigger what is inferred to be an authentication bypass, which also changes scope and could affect additional connected components.
OpenCVE Enrichment