Impact
A flaw in the Security component of Oracle PeopleSoft Enterprise SCM Manufacturing 9.2 allows an attacker with network reachability over HTTP to authenticate without credentials and obtain unrestricted read access to sensitive data. The vulnerability leads to a high confidentiality impact without affecting integrity or availability, as described in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N.
Affected Systems
Oracle PeopleSoft Enterprise SCM Manufacturing 9.2 is the only product and version explicitly listed as affected. No other versions or products were mentioned in the advisory.
Risk and Exploitability
The CVSS base score of 7.5 indicates a medium to high severity for an unauthenticated attacker. The EPSS score of less than 1% suggests the probability of exploitation in the wild is low, and the vulnerability is currently not listed in the CISA KEV catalog. Inferred from the description, the likely attack vector is over the network via HTTP, requiring no authentication or special user privileges. The impact would be unauthorized access to all data exposed through PeopleSoft, posing a significant confidentiality risk.
OpenCVE Enrichment