Impact
The vulnerability in Oracle PeopleSoft Enterprise SCM Inventory is an improper access control flaw (CWE‑284). An unauthenticated attacker can send HTTP requests that result in unauthorized access to sensitive data and the ability to update or delete that data. The flaw causes significant confidentiality damage and a moderate integrity impact, as reflected by the CVSS 3.1 Base Score of 8.2. The attack does not require user interaction and can be performed from any network location that can reach the HTTP interface, making remote compromise possible.
Affected Systems
Oracle Corporation PeopleSoft Enterprise SCM Inventory version 9.2 is affected. No other versions or products are listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability, and the EPSS score of less than 1% suggests a low but non‑zero probability of exploitation. Since the flaw is not listed in CISA KEV, there is no current evidence of widespread exploitation. The attack vector is inferred to be remote via unauthenticated HTTP traffic, and successful exploitation would allow the attacker to read or modify accessible data.
OpenCVE Enrichment