Impact
The vulnerability exists in the Manage Requisition Status component of PeopleSoft Enterprise SCM eProcurement. An attacker who can reach the application via standard HTTP does not need to authenticate and can obtain unauthorized access to critical data and can also update, insert, or delete data that is normally protected. The flaw is a full authorization bypass that brings confidentiality to a high level and a moderate integrity impact, as reflected in the CVSS score of 9.3.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise SCM eProcurement version 9.2 is affected. Other Oracle PeopleSoft products that interact closely with eProcurement may also be impacted due to a scope change, but no other specific versions are listed.
Risk and Exploitability
The CVSS score of 9.3 categorizes this vulnerability as Critical. The EPSS score of less than 1% indicates that exploitation is considered unlikely at present, and the vulnerability is not yet listed in the CISA KEV catalog. Nevertheless, the attack vector is a straightforward HTTP request to the exposed component, and because no authentication is required, the risk to an organization that exposes the service to the public or an untrusted network is high.
OpenCVE Enrichment