Impact
A vulnerability in the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil allows an unauthenticated attacker with network access via HTTP to compromise the application. The flaw involves improper handling of authentication and authorization, which maps to weaknesses such as information exposure, insufficient privilege checks, weak authentication controls, and lack of proper access restrictions. Successful exploitation results in complete takeover of the application, providing an attacker full control over confidential data, system integrity, and availability.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1 is affected. No other product versions are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 9.8 marks this vulnerability as critical, while the EPSS score of less than 1% indicates a very low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the weakness via unauthenticated HTTP traffic to the exposed Integration endpoint, making the attack path straightforward for anyone with network reach to the target server.
OpenCVE Enrichment