Impact
The vulnerability resides in the Security component of Oracle PeopleSoft Enterprise SCM Supplier Contract Management 9.2 and is a local privilege escalation flaw (CWE‑269). A user with low‑privileged logon on the host can exploit the weakness to elevate privileges and compromise the application, leading to a full takeover with loss of confidentiality, integrity, and availability.
Affected Systems
Oracle PeopleSoft Enterprise SCM Supplier Contract Management version 9.2 is affected. The flaw exists in the Security module and may be exercised by anyone who has local access credentials to the infrastructure hosting the application, potentially impacting other integrated components within the same deployment.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates high severity impacts across confidentiality, integrity, and availability. The EPSS score of less than 1 % suggests a low likelihood of current wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the local attack vector and low‑privilege requirement mean an attacker who gains local credentials could elevate privileges, trigger a scope change, and ultimately seize the application, with cascading effects on any co‑deployed systems.
OpenCVE Enrichment