Description
Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Agile Product Lifecycle Management for Process version 6.2.4 allows an unauthenticated attacker to bypass authorization controls in the Product Quality Management component. By sending HTTP requests without authentication, the attacker can create, modify, or delete critical data, and can also read all data exposed through the application. This results in a loss of confidentiality and integrity for the data without impacting availability.

Affected Systems

Only the 6.2.4 release of Oracle Agile Product Lifecycle Management for Process is identified as vulnerable. The Product Quality Management component is the part of the product affected according to the vendor advisory.

Risk and Exploitability

The CVSS base score of 9.1 indicates a very high exploitation risk, with primary impacts on confidentiality and integrity. The EPSS score is less than 1 %, suggesting a low probability of widespread exploitation at the moment, and the vulnerability is not yet catalogued in CISA KEV. Attackers can reach the vulnerable system over network HTTP connections, enabling authorization bypass without any credential or authentication requirements. The conditions for exploitation are minimal: network access to the application and an unauthenticated client capable of sending HTTP requests.

Generated by OpenCVE AI on August 4, 2026 at 01:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for CVE‑2026‑61184 as published in the July 2026 CPU release.
  • Restrict network access to the Oracle Agile Product Lifecycle Management application by placing it behind a VPN or firewall until the patch is applied.
  • Continuously monitor application logs for unusual read, write, or delete operations that could indicate exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authorization Bypass in Oracle Agile Product Lifecycle Management 6.2.4

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Authorization Bypass in Oracle Agile Product Lifecycle Management 6.2.4

Sat, 01 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Manipulation Vulnerability in Oracle Agile Product Lifecycle Management

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Data Manipulation Vulnerability in Oracle Agile Product Lifecycle Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Product Lifecycle Management for Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle agile Product Lifecycle Management For Process
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Product Lifecycle Management For Process
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Agile Product Lifecycle Management For Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-05T13:48:37.525Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61184

cve-icon Vulnrichment

Updated: 2026-07-23T15:24:47.969Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses