Impact
The flaw in the Staffing component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina allows an attacker who can reach the application over HTTP to compromise the system. The vulnerability is described as easily exploitable, enabling a low‑privileged attacker to achieve full takeover of the product. A successful exploit would allow the adversary to read, modify, and delete data as well as execute arbitrary code, resulting in complete loss of confidentiality, integrity, and availability.
Affected Systems
Oracle PeopleSoft distributes the affected product as PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1. No other Oracle products are specifically listed as impacted, but the description indicates that a successful attack may broaden the scope to other modules that share the same environment.
Risk and Exploitability
The attack vector is a remote HTTP request from a low‑privileged attacker on the network. The CVSS 3.1 Base Score of 9.9 demonstrates critical impact, while the EPSS score of less than 1% indicates that exploitation is not yet widespread. The weakness stems from improper access control (CWE-284), enabling the attacker to cross from a restricted user context to full system control, potentially impacting additional PeopleSoft components.
OpenCVE Enrichment