Impact
This vulnerability exists in the Inventory component of Oracle PeopleSoft Enterprise FIN Inventory Brazil version 9.1. It allows a locally logged‑in, low‑privileged user to compromise the application, potentially leading to full system takeover. The flaw is assessed with a CVSS 3.1 Base Score of 7.8, reflecting confidentiality, integrity, and availability impacts. It is identified as CWE‑269.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise FIN Inventory Brazil, version 9.1, operating on any supported infrastructure where the application is deployed.
Risk and Exploitability
The attack vector is local, requiring only that the attacker have a user logon on the host. The privilege level needed is low, the attack is not required to be remote or involve user interaction, and the flaw is readily exploitable. With a CVSS score of 7.8 and an EPSS score of <1%, the risk remains high for environments that still run the vulnerable version.
OpenCVE Enrichment