Impact
The flaw exists in the security component of Oracle PeopleSoft Enterprise SCM Order Management 9.2. A low‑privileged user who can log on locally to the machine where the application is running can exploit the vulnerability. The attacker can compromise the application and achieve full takeover, resulting in complete loss of confidentiality, integrity, and availability. The weakness is captured by CWE‑269 and CWE‑284 and is quantified in CVSS score 7.8 with vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise SCM Order Management version 9.2 is affected. No other versions were listed as impacted by the official data.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity if the flaw is exploited. The EPSS score is less than 1 %, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attack requires local login with low privileges, making the attack vector local. Systems that allow local access face a high potential impact, but the likelihood of exploitation remains low based on available data.
OpenCVE Enrichment