Impact
Vulnerability in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1 allows an unauthenticated attacker to send crafted HTTP requests that bypass authentication checks (CWE‑287) and gain unauthorized access to privileged functions (CWE‑284). The flaw also reveals a privilege misconfiguration (CWE‑306) that threatens confidentiality, integrity, and availability. Successful exploitation leads to full takeover of the PeopleSoft instance, enabling the attacker to read, modify, or delete data and disrupt normal operations.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1, specifically the eProcurement component, is affected. The vulnerability is present only in the 9.1 release of the Brazil‑centric common objects package.
Risk and Exploitability
The CVSS v3.1 base score of 8.1 signals high severity across all impact submetrics. EPSS is reported as <1%, indicating a low current exploitation rate, and the flaw is not in CISA's KEV catalog. Per the description, the attacker requires only network access to the HTTP endpoint—no credentials or elevated privileges are needed. The likely attack vector is over the public or corporate network, and the vulnerability can be exercised by any remote party able to reach the vulnerable URL.
OpenCVE Enrichment