Impact
A weakness in the Oracle Product Lifecycle Analytics component enables an unauthenticated attacker with network access via HTTP to gain unauthorized access to critical data or complete access to all accessible data, while also allowing a partial denial of service. The flaw results in a significant confidentiality breach and a reduction in availability.
Affected Systems
Oracle Corporation's Product Lifecycle Analytics version 3.6.1 is affected. The vulnerability may also impact other related products in the Oracle Supply Chain ecosystem.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3 and is rated low for exploitation probability with an EPSS score of <1%; it is not currently listed in the CISA KEV catalog. The likely attack vector is a remote network-based HTTP request that bypasses authentication controls to achieve unauthorized data access and disrupt service.
OpenCVE Enrichment