Impact
Oracle Project Manufacturing, part of Oracle E‑Business Suite, has a vulnerability in the PJM Command Center component that allows a low‑privileged attacker with network access via HTTP to read a subset of data. The flaw is described as difficult to exploit and results in a confidentiality impact only, with no effect on integrity or availability.
Affected Systems
Affected systems are Oracle Corporation’s Oracle Project Manufacturing product, version 16, as part of the E‑Business Suite.
Risk and Exploitability
The CVSS Base Score is 3.1 with an EPSS score below 1%, and it is not listed in the CISA KEV catalog. Exploitation requires remote network access over HTTP, low privilege, and no user interaction. Because the attack path is straightforward but the exploitability is considered difficult, the overall risk is low, but the confidentiality impact warrants timely remediation.
OpenCVE Enrichment