Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Published: 2026-01-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to critical data
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in Oracle Agile Product Lifecycle Management for Process (version 6.2.4) allows a low privileged attacker with network access via HTTP to read critical database contents. The weakness is categorized as CWE‑79, a vulnerability that can be leveraged to gain unauthorized data visibility. The impact is a breach of confidentiality, exposing proprietary information across the entire application.

Affected Systems

Oracle Corporation’s Agile Product Lifecycle Management for Process version 6.2.4 is affected. No other versions or products are currently reported to be impacted.

Risk and Exploitability

The CVSS v3.1 score of 6.5 reflects a medium severity with high confidentiality impact, low attack complexity, and low privilege requirements. EPSS indicates only a very low exploitation probability (<1%) and the flaw is not listed in CISA’s KEV catalog. However, the attack vector is network‑based, theoretically reachable by anyone who can reach the HTTP interface, and the vulnerability is described as easily exploitable. Agents with low privileges could alter input or trigger the flaw to retrieve data from the managed system.

Generated by OpenCVE AI on April 18, 2026 at 15:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security update released for Agile PDM 6.2.4 as announced in the January 2026 advisory.
  • Configure the HTTP interface to accept traffic only from trusted IP addresses or tunnel through a VPN to prevent unauthenticated network access.
  • Restrict user roles to the minimum necessary permissions and enforce strong authentication for users who need elevated privileges.
  • If patching is not immediately possible, apply web‑application firewall rules that detect and block potential malicious inputs related to the vulnerability.

Generated by OpenCVE AI on April 18, 2026 at 15:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle Agile Product Lifecycle Management

Wed, 21 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Product Lifecycle Management For Process
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Product Lifecycle Management For Process
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Product Lifecycle Management For Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-01-21T15:03:45.583Z

Reserved: 2026-01-05T18:07:34.711Z

Link: CVE-2026-21944

cve-icon Vulnrichment

Updated: 2026-01-21T15:03:40.427Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:15:57.267

Modified: 2026-01-29T20:47:56.817

Link: CVE-2026-21944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T15:45:04Z

Weaknesses