Impact
The vulnerability is located in the installation component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. It allows an unauthenticated attacker who can reach the system over TCP to execute arbitrary code. Successful exploitation grants complete control over the application, leading to disclosure of all data and interruption of service.
Affected Systems
Oracle Agile Product Lifecycle Management for Process version 6.2.4 is the only affected product. Any deployments of this version that are reachable from the network are vulnerable until patched.
Risk and Exploitability
The CVSS base score of 9.8 signals critical severity. Although the EPSS score is currently under 1 %, the vulnerability can be exploited remotely with no user interaction or credentials. It is not listed in the CISA KEV catalog, but its high impact and ease of exploitation necessitate prompt remediation.
OpenCVE Enrichment