Impact
PeopleSoft Enterprise FIN Common Objects is a financial management application. A flaw in its Security component provides an access control weakness (CWE‑284) that lets attackers send unauthenticated HTTP requests to bypass authentication and permission checks. If exploited, an attacker can read, modify, or delete financial records and gain complete control over the application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle PeopleSoft Enterprise FIN Common Objects version 9.2 is identified as vulnerable. No other versions are confirmed at this time. The flaw is reachable through the HTTP interface exposed by the application, targeting the Security component.
Risk and Exploitability
The base CVSS score of 8.1 signals high severity. An attacker requires network connectivity to the HTTP service and must craft a bypass request, which presents moderate to high effort. The EPSS score of less than 1% indicates a low probability of active exploitation, and the vulnerability is not listed in CISA KEV. However, because the flaw allows complete takeover, the potential impact remains significant and organizations should prioritize remediation.
OpenCVE Enrichment