Impact
The flaw resides in the Primavera Integration component of Oracle PeopleSoft Enterprise FIN Program Management version 9.2. An attacker possessing a low‑privileged network account that can reach the application over HTTP can exploit the vulnerability after a different user performs a single interaction. The successful exploit allows the attacker to gain unrestricted control of the PeopleSoft instance, exposing sensitive data, compromising data integrity, and rendering the application unavailable. This results in a full system compromise with complete confidentiality, integrity and availability impact.
Affected Systems
Oracle PeopleSoft Enterprise FIN Program Management version 9.2 is the only product explicitly listed as affected by the CNA. The advisory does not indicate any other Oracle products are impacted.
Risk and Exploitability
The CVSS 3.1 score of 9.0 classifies the vulnerability as critical, and the EPSS score of less than 1 % indicates that exploitation incidents are currently rare. The vulnerability is not listed in CISA KEV. Exploitation requires network reachability to the application over HTTP, a low‑privileged account, and a prior user interaction to trigger the flaw. Once triggered, the attacker can assume full control of the PeopleSoft environment, covering all confidentiality, integrity, and availability concerns. The associated weaknesses are CWE‑269 (Broken or Incorrect Authentication), CWE‑284 (Improper Authorization) and CWE‑352 (Cross‑Site Request Forgery).
OpenCVE Enrichment