Impact
The vulnerability resides in Oracle PeopleSoft's Enterprise FIN Common Objects Brazil component; specifically, the Staffing module allows an unauthenticated attacker who can reach the service over HTTP to read or retrieve any data stored in the application. The flaw is an improper access control (CWE-284) and provides a confidentiality impact without affecting integrity or availability. Its CVSS 3.1 Base Score of 7.5 indicates a significant potential for data disclosure.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise FIN Common Objects Brazil product, version 9.1, is the only affected system. Administrators and users should check that this version is running and consider applying available fixes.
Risk and Exploitability
Because the flaw is triggerable by any host that can establish an HTTP connection to the system and requires no credentials, the attack vector is straightforward and the risk is considerable. The EPSS score is below 1 %, suggesting that active exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the high confidentiality impact and ease of exploitation warrant immediate remediation.
OpenCVE Enrichment