Impact
A vulnerability in Oracle Agile Product Lifecycle Management for Process (version 6.2.4) allows a low privileged attacker with network access via HTTP to read critical database contents. The weakness is categorized as CWE‑79, a vulnerability that can be leveraged to gain unauthorized data visibility. The impact is a breach of confidentiality, exposing proprietary information across the entire application.
Affected Systems
Oracle Corporation’s Agile Product Lifecycle Management for Process version 6.2.4 is affected. No other versions or products are currently reported to be impacted.
Risk and Exploitability
The CVSS v3.1 score of 6.5 reflects a medium severity with high confidentiality impact, low attack complexity, and low privilege requirements. EPSS indicates only a very low exploitation probability (<1%) and the flaw is not listed in CISA’s KEV catalog. However, the attack vector is network‑based, theoretically reachable by anyone who can reach the HTTP interface, and the vulnerability is described as easily exploitable. Agents with low privileges could alter input or trigger the flaw to retrieve data from the managed system.
OpenCVE Enrichment