Impact
A flaw in the Installation Issues component of Oracle Product Lifecycle Analytics permits an attacker with high‑privileged credentials and HTTP network access to create, delete, or modify critical data and to cause a partial denial of service. Based on the description, it is inferred that missing or insufficient authentication and access‑control checks enable this vulnerability, compromising confidentiality, integrity, and limiting availability of the application.
Affected Systems
Oracle Product Lifecycle Analytics version 3.6.1 is affected. No other versions are listed as vulnerable in the advisory, so only deployments of this specific release are impacted.
Risk and Exploitability
The CVSS 3.1 base score of 6.7 indicates moderate severity, with high impact on confidentiality and integrity and a lower impact on availability. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network‑based via the HTTP interface, and a high‑privilege account or compromised credential is required to benefit from the flaw.
OpenCVE Enrichment