Oracle PeopleSoft Work Order Management Vulnerability Allowing Unauthorized Data Access and Modification

Vulnerability

A vulnerability exists in the PeopleSoft Enterprise FIN Maintenance Management product, specifically within the Work Order Management component, version 9.2. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data, as well as unauthorized read access to certain subsets of data within PeopleSoft Enterprise FIN Maintenance Management.

Impact

Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete data within PeopleSoft Enterprise FIN Maintenance Management.

Added: Oct 21, 2025, 9:10 PM
Updated: Oct 21, 2025, 9:10 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
5.2
remediation
0.0
relevance
0.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.