Impact
PeopleSoft Enterprise FIN Payables 9.2 contains a flaw in its security component that permits an unauthenticated attacker with network access via HTTP to read sensitive financial data without providing credentials. This vulnerability, identified as CWE‑284, allows a compromise of data confidentiality only, as the attack path does not expose integrity or availability weaknesses. The vulnerability manifests by bypassing normal access control checks, enabling the attacker to retrieve any data the application is authorized to serve to a logged‑in user.
Affected Systems
Oracle PeopleSoft Enterprise FIN Payables version 9.2 is affected by this flaw. The product is part of Oracle’s PeopleSoft suite used primarily for financial transaction processing.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 reflects a significant confidentiality impact; the EPSS score of less than 1% indicates a low probability of exploitation at present, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an unauthenticated HTTP connection to the exposed interface; this inference is drawn from the statement that an attacker with network access via HTTP can exploit the vulnerability, implying that any user who can reach the PeopleSoft web server could potentially read sensitive data if the patch is not applied.
OpenCVE Enrichment