Impact
A flaw in Oracle PeopleSoft Enterprise SCM Purchasing allows an attacker with network access to perform unauthorized creations, deletions, or modifications of data, as well as read access to restricted data. The vulnerability exploits insufficient access control, leading to potential loss of data integrity and confidentiality. The impact is confined to the Purchasing component of the PeopleSoft suite and does not affect overall system availability. The weakness is identified as CWE-284, which pertains to improper authorization controls.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise SCM Purchasing version 9.2 is vulnerable. Attackers can exploit this issue only when the affected component is exposed to public or untrusted networks via HTTP. Users of newer versions or those that do not run the Purchasing module are not impacted.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 reflects the high risk of exploitation, primarily due to the lack of authentication required. The EPSS score of less than 1% indicates that, at present, the probability of active exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. However, the mode of operation – an unauthenticated attacker using a simple HTTP request – makes it trivially exploitable by a broad attacker population, emphasizing the importance of remediating this weakness promptly.
OpenCVE Enrichment