Vulnerability in Oracle PeopleSoft FIN Cash Management Component
CVE-2022-21481

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

A vulnerability exists in the PeopleSoft Enterprise FIN Cash Management product from Oracle, which allows low privileged attackers with network access to compromise the system through HTTP. Exploiting this flaw requires human interaction from a different user, increasing the risk of unauthorized data manipulations. Attackers may gain the ability to insert, update, or delete data, along with unauthorized read access to specific financial data. This vulnerability may not only affect the Cash Management product but could also have broader implications on other related components.

Affected Version(s)

PeopleSoft Enterprise FIN Cash Management 9.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.