Impact
The flaw is an improper authorization weakness in Oracle Agile Product Lifecycle Management for Process, enabling a low‑privileged attacker with HTTP access to read, insert, update or delete critical data that the user is not allowed to manipulate. The vulnerability is classified as CWE‑284 (Improper Access Control), and the description indicates that successful exploitation can change the scope and potentially affect other Oracle products. The data impacts are high on confidentiality and moderate on integrity, while availability is not directly affected.
Affected Systems
Oracle Agile Product Lifecycle Management for Process version 6.2.4, part of Oracle Supply Chain’s Product Quality Management component. No other versions or components are listed as vulnerable, but the description notes that successful exploits may change scope and impact additional Oracle products.
Risk and Exploitability
The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N) yields a base score of 7.6, indicating high severity. The EPSS score is below 1 %, showing a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network connectivity over HTTP, a low‑privileged account, and human interaction from a separate user. While the probability of exploitation is low, the potential for unauthorized data access and manipulation presents a significant confidentiality and integrity risk if an attacker succeeds.
OpenCVE Enrichment