Impact
The vulnerability resides in Oracle Project Manufacturing’s PJM Command Center and permits a low‑privileged user with local logon to the underlying infrastructure to gain unauthorized update, insert, or delete rights over accessible data, as well as to induce a partial denial‑of‑service episode. The weakness manifests with a CVSS 3.1 Base Score of 3.6, reflecting modest integrity and availability impacts and no confidentiality compromise. The vector indicates local access (AV:L) with high attack complexity (AC:H), low privilege (PR:L) and no user interaction (UI:N).
Affected Systems
This fault affects Oracle Project Manufacturing version 16, specifically the PJM Command Center component. No other versions or products were identified as impacted in the supplied vendor data.
Risk and Exploitability
With a CVSS score of 3.6 the overall severity is low, and the EPSS score of less than 1% suggests a very low likelihood of being exploited in the wild. The vulnerability is not currently listed in the CISA KEV catalogue. Exploitation requires local logon privileges, implying that an attacker must first compromise or access the infrastructure hosting Oracle Project Manufacturing. From an operational perspective, the risk is confined to data integrity and limited service availability, but mitigations are advised to prevent potential operational disruptions and unauthorized data changes.
OpenCVE Enrichment