Impact
The vulnerability exists in the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina 9.1. It allows an unauthenticated attacker to access the system over HTTP and bypass existing access controls. Successful exploitation provides read access to all critical data, enables unauthorized updates, inserts, or deletions, and can cause a partial denial of service. The weakness is mapped to CWE‑269 (Improper Privilege Escalation) and CWE‑284 (Improper Access Control). The CVSS 3.1 score of 9.9 reflects significant confidentiality, integrity, and availability impact.
Affected Systems
Only Oracle PeopleSoft Enterprise FIN Common Objects Argentina version 9.1 is affected according to the CNA data. No other versions or product lines are listed.
Risk and Exploitability
With a CVSS 9.9 score the vulnerability is high severity, yet the EPSS value of less than 1 % indicates a very low probability of exploitation at the time of analysis. It is not included in the CISA KEV catalog. The attack can be performed from any host that can reach the application via HTTP, requiring no credentials or elevated privileges, which makes it potentially attractive for adversaries with network access to the target.
OpenCVE Enrichment