Impact
The vulnerability exists in the Security component of Oracle PeopleSoft Enterprise SCM Inventory 9.2. An unauthenticated attacker who can reach the application over HTTPS can exploit this flaw to bypass authentication and read any data that the application can serve. The weakness reflects improper authorization (CWE‑284) and results in a confidentiality compromise without affecting integrity or availability.
Affected Systems
Oracle PeopleSoft Enterprise SCM Inventory version 9.2 is affected; no other versions are listed as impacted in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates medium‑high severity, largely due to impact on confidentiality. The EPSS score is less than 1%, showing that real‑world exploitation is currently rare and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can be triggered remotely over HTTPS without authentication, the risk to organizations with network exposure is moderate and requires prompt action.
OpenCVE Enrichment