Impact
Unauthenticated local attackers who have logon to the infrastructure where Oracle Product Lifecycle Analytics runs can exploit a flaw in the installation component that allows unauthorized creation, deletion, or modification of critical data. The vulnerability results in loss of confidentiality and integrity and grants the attacker full control over accessible data, possibly affecting other products within the supply chain.
Affected Systems
Oracle Corporation’s Oracle Product Lifecycle Analytics version 3.6.1 is affected. No other product versions were identified in the advisory.
Risk and Exploitability
The flaw carries a CVSS 3.1 score of 9.0, indicating a high severity impact on confidentiality and integrity. The EPSS score is below 1%, suggesting a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attackers require local system access or logon rights on the infrastructure where the product is deployed; the vulnerability is classified as easily exploitable once those conditions are met, and the scope change can extend its impact to other products.
OpenCVE Enrichment