Impact
The vulnerability stems from a weak access control mechanism in Oracle PeopleSoft Enterprise SCM Manufacturing version 9.2. An unauthenticated attacker who can reach the application over HTTPS can create, delete, or modify critical data. The attack compromises data integrity and confidentiality, potentially exposing or altering all data accessible through the application.
Affected Systems
Oracle Corporation’s PeopleSoft Enterprise SCM Manufacturing product, version 9.2, is affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.4 indicates significant impact on confidentiality and integrity. The EPSS score of less than 1% shows a low probability of exploitation for now, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only network connectivity over HTTPS and no authentication, making the attack path straightforward for an attacker within reach of the application.
OpenCVE Enrichment