Impact
The vulnerability resides in the PJM Command Center component of Oracle Project Manufacturing. It allows an attacker who already has high‑privileged access to the infrastructure where the application runs to create, delete, or modify critical data. This leads to confidentiality and integrity damage, as attackers can change all data the application exposes.
Affected Systems
Oracle Corporation’s Oracle Project Manufacturing version 16 is affected. No other versions were listed as vulnerable.
Risk and Exploitability
The CVSS base score is 5.7, indicating moderate severity, and the EPSS score is below 1 %, showing a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have high privileged logon to the underlying infrastructure, so local or privileged network access is the inferred attack vector. While the risk of exploitation is low, the potential impact on data integrity and confidentiality is significant if a high‑privileged attacker succeeds.
OpenCVE Enrichment