Oracle PeopleSoft Enterprise SCM Purchasing Component Vulnerability Allowing Unauthorized Data Access and Modification

Vulnerability

A vulnerability exists in the PeopleSoft Enterprise SCM Purchasing product, specifically in version 9.2. This easily exploitable issue allows a low-privileged attacker with network access via HTTP to compromise the application. Successful exploitation can lead to unauthorized read access to certain data, as well as unauthorized updates, inserts, or deletions of accessible data within the PeopleSoft Enterprise SCM Purchasing module.

Impact

Exploitation of this vulnerability could result in unauthorized access to read, update, insert, or delete data within the PeopleSoft Enterprise SCM Purchasing application.

Added: Jan 20, 2026, 10:44 PM
Updated: Jan 20, 2026, 10:44 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
3.1
exploitability
4.9
remediation
0.0
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.