Impact
The flaw exists in Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1, within the Purchasing component. An attacker without valid credentials who can reach the system over HTTP can exploit the vulnerability to read or retrieve sensitive business data. The incident would result in a breach of confidentiality, potentially exposing all data available through the PeopleSoft interface.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1, specifically its Purchasing module in the Brazilian deployment.
Risk and Exploitability
The CVSS v3.1 score is 7.5, indicating a high confidentiality impact while authentication is not required. The EPSS score is below 1, and the issue is not listed in CISA KEV. The vulnerability permits unauthenticated network access via HTTP, allowing attackers to directly read data from the application without needing to log in. Such an exploit could lead to complete exposure of all data accessible through the module.
OpenCVE Enrichment