Impact
This vulnerability in Oracle PeopleSoft Enterprise FIN Common Objects Brazil version 9.1 allows an attacker who already holds high‑privilege credentials and can reach the application over the network using T3 or IIOP protocols to compromise the system. Successful exploitation results in full takeover of the application, jeopardizing confidentiality, integrity, and availability. The CVSS vector indicates low attack complexity and no user interaction, but requires high privileges, confirming that the flaw is effectively a privilege‑escalation or improper access‑control weakness.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects Brazil 9.1 is the only publicly identified affected version. No other versions or components are listed as vulnerable in the available data.
Risk and Exploitability
With a CVSS base score of 7.2, the vulnerability falls into the high‑severity range. The EPSS score of 0.00465 indicates a very low exploitation probability, meaning the current likelihood of attack is low; however, the network‑exposed nature and requirement for high‑privilege access suggest that only internal or compromised accounts could trigger the attack. The vulnerability is not yet in the CISA KEV catalog, indicating that no widespread exploitation has been documented, but the risk remains significant for organizations that have not applied the vendor patch.
OpenCVE Enrichment