Impact
The vulnerability resides in the Data Import component of Oracle Agile Product Lifecycle Management for Process. It allows an attacker who has logged onto the underlying infrastructure with high privileges to compromise the application, resulting in full takeover. This leads to complete loss of confidentiality, integrity, and availability of the system, as reflected by a CVSS 3.1 Base Score of 6.7 and a vector indicating local access, low attack complexity, high privileges, no user interaction, and overall impact.
Affected Systems
Oracle Agile Product Lifecycle Management for Process version 6.2.4 is the only version impacted. The vulnerability affects the Oracle Supply Chain product line and is tied to the specified CPE string for that version.
Risk and Exploitability
Although the EPSS score is less than 1% and the issue is not listed in the CISA KEV catalog, the CVSS 3.1 Base Score of 6.7 indicates a moderate‑to‑high severity, reflecting significant confidentiality, integrity, and availability impacts. The local attack vector combined with the ability to take full control of the application presents a high‑severity risk. The need for local, high‑privilege access limits the exposure window, yet the potential impact remains catastrophic if an insider or privileged service account is compromised.
OpenCVE Enrichment