Impact
The vulnerability resides in Oracle PeopleSoft Enterprise SCM Mobile Inventory Management version 9.2. An attacker who already has local access to the infrastructure can exploit this flaw to compromise the application. Exploitation allows them to create, delete, or modify critical data, and to obtain unauthorized read access to any data the application processes. Because the fault changes the scope of the application, a successful attack may also impact other PeopleSoft components that share the same environment.
Affected Systems
Affected systems are Oracle Corporation’s PeopleSoft Enterprise SCM Mobile Inventory Management product, specifically release 9.2. No other versions or products are listed as affected in the available data.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 7.5, with low attack vector (local), high attack complexity, low privilege requirement, and no user interaction, resulting in confidentiality and integrity impact while availability remains unaffected. The EPSS score is less than 1%, indicating a very low but non‑zero probability of exploitation. The issue is not currently listed in CISA’s KEV catalog. The likely attack path requires a threat actor to first achieve local log‑on privileges on the host running PeopleSoft, then use the application’s insecure access control logic to elevate their reach within the data set.
OpenCVE Enrichment