Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper authorization weakness in Oracle Agile Product Lifecycle Management for Process, enabling a low‑privileged attacker with HTTP access to read, insert, update or delete critical data that the user is not allowed to manipulate. The vulnerability is classified as CWE‑284 (Improper Access Control), and the description indicates that successful exploitation can change the scope and potentially affect other Oracle products. The data impacts are high on confidentiality and moderate on integrity, while availability is not directly affected.

Affected Systems

Oracle Agile Product Lifecycle Management for Process version 6.2.4, part of Oracle Supply Chain’s Product Quality Management component. No other versions or components are listed as vulnerable, but the description notes that successful exploits may change scope and impact additional Oracle products.

Risk and Exploitability

The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N) yields a base score of 7.6, indicating high severity. The EPSS score is below 1 %, showing a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires network connectivity over HTTP, a low‑privileged account, and human interaction from a separate user. While the probability of exploitation is low, the potential for unauthorized data access and manipulation presents a significant confidentiality and integrity risk if an attacker succeeds.

Generated by OpenCVE AI on August 4, 2026 at 01:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch for Agile Product Lifecycle Management for Process 6.2.4.
  • Restrict HTTP access to the application by limiting network connectivity to trusted hosts or via VPN.
  • Review and tighten user roles and permissions to ensure proper access control for data read and write operations.
  • Enable logging and actively monitor for suspicious data access or modification attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthorized data access and manipulation via improper authorization in Oracle Agile PDM

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthorized data access and manipulation via improper authorization in Oracle Agile PDM

Tue, 28 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Manipulation via Low-Privilege HTTP Attack in Oracle Agile Product Lifecycle Management for Process 6.2.4

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Manipulation via Low-Privilege HTTP Attack in Oracle Agile Product Lifecycle Management for Process 6.2.4

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-601
CWE-640
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized update, insert or delete access to some of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle agile Product Lifecycle Management For Process
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Product Lifecycle Management For Process
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Agile Product Lifecycle Management For Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-05T13:49:37.396Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61181

cve-icon Vulnrichment

Updated: 2026-07-23T15:27:35.533Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password