Impact
The flaw in Oracle Agile Product Lifecycle Management for Process allows an attacker with low privileges and network connectivity to the application via HTTP to trigger a takeover. The vulnerability results in full compromise of the system, affecting confidentiality, integrity, and availability. It stems from weaknesses enumerated in CWE‑269, CWE‑284, CWE‑287, and CWE‑306, which allow the attacker to elevate privileges, bypass authentication, and manipulate configuration.
Affected Systems
Oracle Agile Product Lifecycle Management for Process version 6.2.4 is affected. This component is part of Oracle Supply Chain’s Product Quality Management.
Risk and Exploitability
The CVSS score of 8.8 categorizes the vulnerability as critical, while the EPSS score of less than 1% indicates a very low current exploitation probability. The KEV list does not include this flaw. The attack vector is network based; an adversary only needs to send crafted HTTP requests to an exposed instance, and no user interaction is required.
OpenCVE Enrichment