Impact
A flaw in PeopleSoft Enterprise FIN Common Objects Argentina’s eProcurement component allows an unauthenticated user to send HTTP requests that can create, delete, or alter critical data, read restricted information, and trigger a partial denial of service. The weakness violates access control (CWE‑284) and authentication (CWE‑306), enabling an attacker to bypass required credentials entirely.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise FIN Common Objects Argentina version 9.1 is affected; any installation exposing the eProcurement interface to a network is vulnerable, and the scope change may impact related PeopleSoft modules.
Risk and Exploitability
The CVSS base score of 9.9 indicates critical severity, with network access over HTTP required and low effort to exploit. The EPSS score indicates a very low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Successful exploitation can lead to unauthorized creation, deletion, or modification of data, unauthorized read access, and a partial denial of service, potentially propagating to other PeopleSoft components because of the identified scope change.
OpenCVE Enrichment