Oracle PeopleSoft Work Order Management Vulnerability Allowing Unauthorized Data Access and Modification
Vulnerability
A vulnerability exists in the PeopleSoft Enterprise FIN Maintenance Management product, specifically within the Work Order Management component, version 9.2. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation could lead to unauthorized updates, inserts, or deletions of accessible data, as well as unauthorized read access to certain subsets of data within PeopleSoft Enterprise FIN Maintenance Management.
Impact
Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete data within PeopleSoft Enterprise FIN Maintenance Management.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
