Impact
The vulnerability resides in the eSettlements component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina. An unauthenticated attacker who can reach the physical communication segment attached to the hardware where the application runs can exploit the flaw to obtain unauthorized read access to critical data and, in some instances, unauthorized write or delete operations. The flaw aligns with information disclosure (CWE‑200) and authorization bypass (CWE‑284) and carries a CVSS 3.1 base score of 8.2, indicating high confidentiality impact and moderate integrity impact.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects Argentina version 9.1 is affected. No other versions or products are explicitly listed, but the description notes that successful exploitation may spill over to related PeopleSoft components.
Risk and Exploitability
The CVSS score of 8.2 highlights a severe risk, while an EPSS score of less than 1 % suggests that exploitation is currently unlikely and the vulnerability is not listed in the CISA KEV catalog. The flaw can be leveraged only when an attacker has physical or local network access to the underlying hardware, so the attack vector is local. The vulnerability allows unauthenticated reading of critical data and, for some data, unauthorized update, insert, or delete operations, and could potentially affect additional PeopleSoft components due to the mentioned scope change.
OpenCVE Enrichment