Impact
The vulnerability exists in the Reporting component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. It allows an unauthenticated attacker with network access over HTTP to gain remote code execution and ultimately take full control of the application. The vulnerability is based on improper authentication enforcement (CWE-287) and missing authentication checks (CWE-306), leading to complete loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Agile Product Lifecycle Management for Process version 6.2.4, used within Oracle Supply Chain, deployed on networked servers accessible via HTTP. No other releases are identified as vulnerable and the affected variable is specific to this version.
Risk and Exploitability
The CVSS v3.1 base score of 9.8 indicates a severe impact. The EPSS score of less than 1% suggests low current exploitation activity, but the flaw is easily exploitable without authentication and can be targeted from any network location with HTTP access. It is not included in the CISA KEV catalog, so no known exploits are publicly documented, yet the risk remains significant because exploitation would give the attacker full system takeover. The likely attack vector is sending crafted HTTP requests to the Reporting endpoint to achieve remote code execution; this inference is based on the stated network‑access requirement.
OpenCVE Enrichment