Impact
The vulnerability in Oracle Agile Product Lifecycle Management for Process version 6.2.4 allows an unauthenticated attacker to bypass authorization controls in the Product Quality Management component. By sending HTTP requests without authentication, the attacker can create, modify, or delete critical data, and can also read all data exposed through the application. This results in a loss of confidentiality and integrity for the data without impacting availability.
Affected Systems
Only the 6.2.4 release of Oracle Agile Product Lifecycle Management for Process is identified as vulnerable. The Product Quality Management component is the part of the product affected according to the vendor advisory.
Risk and Exploitability
The CVSS base score of 9.1 indicates a very high exploitation risk, with primary impacts on confidentiality and integrity. The EPSS score is less than 1 %, suggesting a low probability of widespread exploitation at the moment, and the vulnerability is not yet catalogued in CISA KEV. Attackers can reach the vulnerable system over network HTTP connections, enabling authorization bypass without any credential or authentication requirements. The conditions for exploitation are minimal: network access to the application and an unauthenticated client capable of sending HTTP requests.
OpenCVE Enrichment