Impact
Vulnerability in Oracle PeopleSoft Enterprise FIN Lease Administration 9.2 allows an attacker who can log on to the underlying infrastructure to create, delete or modify data and gain unauthorized access to all accessible PeopleSoft data. The flaw permits low‑privileged users to bypass normal access controls, resulting in confidentiality and integrity violations that may affect all data stored in the Lease Administration module. The weakness is a Weak Access Control flaw (CWE‑284).
Affected Systems
Affected vendor and product are Oracle Corporation’s PeopleSoft Enterprise FIN Lease Administration version 9.2. No other versions are listed as affected. The vulnerability originates in the Lease Administration component, and Oracle’s security advisory references this single product and version, with no additional product mappings in the CPE list.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity vulnerability when accounting for confidentiality and integrity impacts. Given the local attack vector, the vulnerability is exploitable by anyone who can log on to the system with low privileges, and because the scope is changed, exploitation can affect a broader set of data than originally intended. The EPSS score of 0.00088 (≈0.088%) indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV, but the potential for significant data loss remains high. Exfiltration or data tampering may occur without user interaction.
OpenCVE Enrichment