Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle Agile Product Lifecycle Management for Process allows an attacker with low privileges and network connectivity to the application via HTTP to trigger a takeover. The vulnerability results in full compromise of the system, affecting confidentiality, integrity, and availability. It stems from weaknesses enumerated in CWE‑269, CWE‑284, CWE‑287, and CWE‑306, which allow the attacker to elevate privileges, bypass authentication, and manipulate configuration.

Affected Systems

Oracle Agile Product Lifecycle Management for Process version 6.2.4 is affected. This component is part of Oracle Supply Chain’s Product Quality Management.

Risk and Exploitability

The CVSS score of 8.8 categorizes the vulnerability as critical, while the EPSS score of less than 1% indicates a very low current exploitation probability. The KEV list does not include this flaw. The attack vector is network based; an adversary only needs to send crafted HTTP requests to an exposed instance, and no user interaction is required.

Generated by OpenCVE AI on August 4, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch or upgrade to a non‑affected version as detailed in the Oracle CPU Jul 2026 advisory.
  • Restrict HTTP access to the Agile Product Lifecycle Management for Process installation, limiting connections to trusted hosts or IP ranges.
  • Monitor application logs for abnormal or repeated HTTP requests that could indicate exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Exploit Enables Full Takeover of Oracle Agile Product Lifecycle Management

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Exploit Enables Full Takeover of Oracle Agile Product Lifecycle Management

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Full Takeover of Oracle Agile Product Lifecycle Management for Process

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Attack Enables Full Takeover of Oracle Agile Product Lifecycle Management for Process

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Product Lifecycle Management For Process
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Product Lifecycle Management For Process
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Product Lifecycle Management For Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:04.910Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61179

cve-icon Vulnrichment

Updated: 2026-07-23T15:29:43.889Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function