Impact
A weakness in the security component of Oracle PeopleSoft Enterprise SCM Order Management, identified as CWE-284 (Access Control), allows an attacker who is not authenticated to manipulate or read critical data over HTTP. The flaw can lead to the creation, deletion, or modification of orders and related information, directly compromising confidentiality and integrity. Such changes could disrupt business processes, lead to financial loss, or create legal exposure for the organization.
Affected Systems
Oracle PeopleSoft Enterprise SCM Order Management version 9.2 is affected. No other versions were explicitly listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 marks this as a critical vulnerability. The attack vector is over the network via HTTP, requires no authentication, and presents minimal effort for automated exploitation, albeit a very low EPSS of less than 1%. The flaw is not yet in the CISA KEV catalog, but its high severity and network accessibility make it a high priority for remediation. An attacker can directly alter or read order data, potentially opening doors for further privilege enhancement or data exfiltration.
OpenCVE Enrichment