Executive brief
A vulnerability exists in Oracle PeopleSoft's financial aid management software, specifically within the component used for calculating student financial needs. An individual with basic access to the server where the software is installed could exploit this flaw to view sensitive financial aid data. This could lead to the unauthorized exposure of private student information or critical institutional financial records.
Technical details
An information disclosure vulnerability exists in the FM Need Analysis Calculator component of Oracle PeopleSoft Enterprise CS Financial Aid version 9.2.38. The flaw is categorized as easily exploitable by a low-privileged attacker who has local logon access to the underlying infrastructure where the application executes. Successful exploitation allows the attacker to bypass intended confidentiality controls, resulting in unauthorized access to critical data or a complete dump of all data accessible by the Financial Aid component. The attack vector is local (AV:L), requiring no user interaction (UI:N) and having no impact on system integrity or availability. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle PeopleSoft Enterprise CS Financial Aid 9.2.38
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed