Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the Reporting component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. It allows an unauthenticated attacker with network access over HTTP to gain remote code execution and ultimately take full control of the application. The vulnerability is based on improper authentication enforcement (CWE-287) and missing authentication checks (CWE-306), leading to complete loss of confidentiality, integrity, and availability.

Affected Systems

Oracle Agile Product Lifecycle Management for Process version 6.2.4, used within Oracle Supply Chain, deployed on networked servers accessible via HTTP. No other releases are identified as vulnerable and the affected variable is specific to this version.

Risk and Exploitability

The CVSS v3.1 base score of 9.8 indicates a severe impact. The EPSS score of less than 1% suggests low current exploitation activity, but the flaw is easily exploitable without authentication and can be targeted from any network location with HTTP access. It is not included in the CISA KEV catalog, so no known exploits are publicly documented, yet the risk remains significant because exploitation would give the attacker full system takeover. The likely attack vector is sending crafted HTTP requests to the Reporting endpoint to achieve remote code execution; this inference is based on the stated network‑access requirement.

Generated by OpenCVE AI on August 4, 2026 at 16:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to a patched release of Oracle Agile Product Lifecycle Management for Process that removes the reporting component flaw.
  • If the patch cannot be applied immediately, restrict HTTP access to the application to trusted IP addresses or VPN connections so only authorized internal users can reach the Reporting endpoint.
  • Enable detailed logging for all requests to the Reporting service and regularly review logs for anomalous activity; consider deploying a web application firewall that filters suspicious requests.

Generated by OpenCVE AI on August 4, 2026 at 16:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Agile Product Lifecycle Management 6.2.4

Sat, 01 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via HTTP in Oracle Agile Product Lifecycle Management 6.2.4

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Reporting Component in Oracle Agile Product Lifecycle Management 6.2.4
Weaknesses CWE-284
CWE-94

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Code Execution via Reporting Component in Oracle Agile Product Lifecycle Management 6.2.4
Weaknesses CWE-284
CWE-287
CWE-306
CWE-94
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Reporting). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in takeover of Oracle Agile Product Lifecycle Management for Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Product Lifecycle Management For Process
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Product Lifecycle Management For Process
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Product Lifecycle Management For Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:17.173Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61183

cve-icon Vulnrichment

Updated: 2026-07-23T15:20:35.123Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function