Impact
The flaw in Oracle Project Manufacturing’s PJM Command Center allows a high‑privileged attacker who can log into the underlying infrastructure to compromise the application. Once exploited, the attacker can read critical data, or even gain complete access to all data the application can reach, and can perform unauthorized updates, inserts or deletes. Only confidentiality and integrity of data are affected, with availability left unchanged.
Affected Systems
Oracle Project Manufacturing version 16, component PJM Command Center, administered by Oracle Corporation. No public patch or upgrade path is listed in the data provided.
Risk and Exploitability
The CVSS v3.1 base score is 4.7, indicating moderate severity. Exploitation requires local access, high attack complexity, and high privileges, with no user interaction. The EPSS score is less than 1%, suggesting a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. Nonetheless, the vulnerability poses a significant internal threat because it enables privileged users or attackers who have gained server access to obtain or modify sensitive project data, potentially compromising business processes.
OpenCVE Enrichment