Impact
A flaw in the Security component of Oracle PeopleSoft Enterprise SCM Order Management 9.2 allows an unauthenticated attacker with network access via HTTPS to breach the application, enabling unauthorized read of critical data or full access to all data exposed by the system. The vulnerability results in a loss of confidentiality with no impact on integrity or availability.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise SCM Order Management, version 9.2. Only that release is affected by this issue.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 marks this vulnerability as high severity, while the EPSS score of less than 1% indicates a very low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is HTTPS network access; the attacker does not need authenticated credentials to trigger the flaw and can submit crafted requests over SSL to obtain confidential data.
OpenCVE Enrichment