Impact
The vulnerability resides in the eProcurement component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina. It is a privilege‑control weakness that allows an unauthenticated attacker with network connectivity to HTTP to create, delete, or modify critical data. The impact level is high, affecting both confidentiality and integrity of all accessible data, while application availability remains unaffected.
Affected Systems
Oracle Corporation, PeopleSoft Enterprise FIN Common Objects Argentina version 9.1 is affected. No other versions or products are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score is 9.1, indicating critical severity. The EPSS score is below 1%, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely via direct HTTP access to the PeopleSoft application, requiring no authentication or special privileges. Successful exploitation permits an attacker to modify or delete data or gain full read access to all data within the application.
OpenCVE Enrichment