Impact
This flaw in the Integration component of Oracle PeopleSoft Enterprise FIN Manufacturing Brazil allows an unauthenticated attacker to connect via HTTPS and fully compromise the application. The vulnerability stems from a failure to enforce authentication and missing access control, resulting in complete takeover. Exploitation would grant an attacker control over all business processes and expose sensitive financial data, with severe impacts on confidentiality, integrity, and availability.
Affected Systems
Oracle PeopleSoft Enterprise FIN Manufacturing Brazil version 9.1 is the only affected release. The vulnerability specifically references the Integration component, so deployments that include this component are at risk. No other versions or components are identified as impacted.
Risk and Exploitability
The CVSS base score of 9.8 denotes critical risk, while the EPSS score of less than 1 % indicates a low probability of current exploitation. The attack can be carried out with no authentication from any machine that can reach the product’s HTTPS interface. The vulnerability is not listed in the CISA KEV catalog, but the high severity remains a significant concern. If exploited, the attacker would achieve complete control, jeopardizing all finance and manufacturing operations.
OpenCVE Enrichment