Impact
A low‑privileged attacker who has gained a login to the infrastructure on which Oracle PeopleSoft Enterprise FIN Engineering Brazil runs can exploit a flaw that does not require user interaction. The vulnerability permits the attacker to raise privileges locally, ultimately allowing complete takeover of the application and its data. This is a classic privilege‑management weakness (CWE‑269) that directly compromises confidentiality, integrity, and availability.
Affected Systems
Only Oracle’s PeopleSoft Enterprise FIN Engineering Brazil version 9.1 is listed as affected. No other products or versions are reported to be impacted.
Risk and Exploitability
The CVSS 3.1 base score of 7.8, combined with low attack complexity and low privilege prerequisites, means the attacker must be present on the same host but needs no additional credentials. The EPSS score of less than 1 % indicates very low current exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog, though that does not diminish the potential severity if a local user becomes compromised. Successful exploitation would grant the attacker full control over the application and any data it manages.
OpenCVE Enrichment