Impact
Oracle PeopleSoft Enterprise FIN Manufacturing Argentina 9.1 contains an unauthenticated access‑control flaw in the Manufacturing component that allows an attacker who can reach the system over HTTP to create, delete, or modify critical manufacturing data and to read all data accessible through the application. The vulnerability bypasses all authentication checks, giving the attacker unrestricted authority over the data layer, thereby compromising the confidentiality and integrity of critical business information.
Affected Systems
All installations of Oracle PeopleSoft Enterprise FIN Manufacturing Argentina version 9.1 distributed by Oracle Corporation are affected. The flaw resides specifically in the Manufacturing component of the product. No other versions or products are currently identified as vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 9.1 identifies this issue as critical, indicating severe potential damage to confidentiality and integrity. The EPSS score of less than 1% suggests that active exploitation at this time is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only unauthenticated network access to an HTTP endpoint, so no additional privileges or software are needed. If exploited, an attacker can modify or delete important manufacturing data and read all data accessible through the application.
OpenCVE Enrichment