Impact
The vulnerability in Oracle Agile Product Lifecycle Management for Process 6.2.4 allows a low‑privileged attacker with network access via HTTP to fully compromise the application, potentially gaining complete control over the system. This results in loss of confidentiality, integrity, and availability, effectively enabling a takeover of the process lifecycle management environment. The flaw stems from improper authentication (CWE-287), missing authentication (CWE-306) and privilege escalation (CWE-269) conditions that can be abused through typical HTTP requests.
Affected Systems
Oracle Corporation’s Agile Product Lifecycle Management for Process, version 6.2.4. No other versions are listed as affected at this time.
Risk and Exploitability
The CVSS 3.1 base score is 8.8, indicating high severity. The EPSS score is below 1%, suggesting a low probability of exploitation, yet the vulnerability is considered easily exploitable and is not yet listed in the CISA KEV catalog. Attackers would use normal HTTP traffic to interact with the product, requiring only low privileges and network access to the vulnerable endpoint. No additional constraints such as elevated privileges or special user roles are mentioned, meaning the attack can proceed from any user with limited rights.
OpenCVE Enrichment