Impact
Vulnerability in Oracle PeopleSoft Enterprise FIN Common Objects Argentina affects the Staffing component and allows an attacker who can reach the application over HTTP with low privileges to compromise the system. Successful exploitation results in full takeover of the application, producing confidentiality, integrity, and availability impacts as indicated by the referenced CVSS vector. The weakness is due to improper authentication and access control controls (CWE‑269, 284, 287, 306).
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects Argentina, version 9.1, is impacted. The affected product is specifically the Staffing module within this version.
Risk and Exploitability
With a CVSS 3.1 base score of 8.8, the vulnerability is high severity. The EPSS score is less than 1 %, indicating a very low but non-zero probability of exploitation. It is not listed in the CISA KEV catalog. The low attack complexity and low privileged requirement mean that a threat actor with network access to the HTTP interface (for example, an internal adversary or a compromised device) can trigger the exploit. The flaw involves authentication and access‑control weaknesses (CWE‑269, 284, 287, 306) that allow the attacker to gain unrestricted control of the application without legitimate credentials.
OpenCVE Enrichment