Impact
The vulnerability in Oracle Project Manufacturing allows an attacker with high‑privileged local access on the infrastructure that hosts the application to create, delete or modify critical data and to obtain full read access to all data managed by Oracle Project Manufacturing. This can lead to data loss, corruption and exposure of confidential information. The weakness is a CWE‑284 (Improper Access Control).
Affected Systems
Affected is Oracle Project Manufacturing, component PJM Command Center, version 16 of Oracle E‑Business Suite, distributed by Oracle Corporation.
Risk and Exploitability
The base CVSS 3.1 score is 5.7, reflecting moderate impact on confidentiality and integrity but no availability effect. The EPSS score is less than 1%, indicating a very low probability that the vulnerability is exploited in the wild. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Exfiltration requires local access with high privileges, making the attack vector local and the attacker's ability to gain further escalation constrained to existing privileged accounts.
OpenCVE Enrichment