Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published: 2026-04-21
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized read access to sensitive data (confidentiality compromise)
Action: Assess Impact
AI Analysis

Impact

The flaw in Oracle Agile Product Lifecycle Management for Process version 6.2.4 permits an attacker with low privileges to access the system over HTTP and read data that should be restricted. The vulnerability is reported as a low‑complexity, network‑based exploit that results in a confidentiality compromise, as reflected by the CVSS 3.1 score of 4.3 (C L). Based on the description, it is inferred that the weakness arises from inadequate authorization checks in the Product Quality Management component, leading to information disclosure.

Affected Systems

Oracle Corporation’s Agile Product Lifecycle Management for Process, part of Oracle Supply Chain Management, is affected. The only explicitly listed vulnerable release is version 6.2.4; newer releases are presumed patched. No other versions or components are mentioned.

Risk and Exploitability

Based on the description, it is inferred that the attack can be launched over the public network without authentication and only requires low privileges, suggesting a moderate risk of exploitation. The CVSS Base Score of 4.3 indicates a moderate impact on confidentiality, but since no EPSS score is available and the vulnerability is not listed in KEV, we cannot determine the current exploitation prevalence, and it is inferred that hacking activity is not yet widespread. However, the ease of use of the flaw means organizations should assess the potential data exposure promptly and consider remediation or additional controls.

Generated by OpenCVE AI on April 22, 2026 at 04:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Agile Product Lifecycle Management for Process to a version that includes the Oracle patch released in the April 2026 security alert.
  • Configure the application so that all data‑retrieval endpoints require authentication and enforce role‑based access control to prevent unauthorized read access.
  • Isolate the application behind a network perimeter that restricts HTTP traffic to known administrative contacts, and block unauthenticated network access from untrusted hosts.
  • Enable comprehensive logging and monitor for any unauthorized read attempts, then alert security personnel accordingly.

Generated by OpenCVE AI on April 22, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 05:15:00 +0000

Type Values Removed Values Added
Title Oracle Agile PDM for Process 6.2.4 HTTP Read Access Vulnerability
Weaknesses CWE-200
CWE-284

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
First Time appeared Oracle
Oracle agile Product Lifecycle Management For Process
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Product Lifecycle Management For Process
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Oracle Agile Product Lifecycle Management For Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-04-21T20:35:29.220Z

Reserved: 2026-03-26T19:48:45.678Z

Link: CVE-2026-34296

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-21T21:16:34.610

Modified: 2026-04-21T21:16:34.610

Link: CVE-2026-34296

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T05:00:09Z

Weaknesses