Executive brief
Oracle PeopleSoft Enterprise SCM Inventory, a software suite used by organizations to manage supply chain and inventory operations, contains a security vulnerability. An unauthorized attacker can exploit this flaw over the network to gain access to sensitive business data. This could result in the exposure of critical inventory records or complete access to all data managed by the affected component.
Technical details
A vulnerability exists in the Security component of Oracle PeopleSoft Enterprise SCM Inventory version 9.2. The flaw is classified as easily exploitable and allows an unauthenticated attacker with network access via HTTPS to compromise the system. The vulnerability specifically impacts confidentiality, potentially allowing an attacker to read all data accessible to the SCM Inventory component. The attack requires no user interaction or special privileges. While the specific CWE is not detailed in the advisory, the impact is limited to data exposure (Confidentiality: High) without affecting system integrity or availability.
Affected products
- Oracle PeopleSoft Enterprise SCM Inventory 9.2
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability as part of the July 2026 Critical Patch Update.
- 2026-07-21: disclosed