Impact
The vulnerability is located in the installation component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. The CVE states that an attacker with physical access to the communication segment attached to the hardware can exploit this flaw without authentication. The flaw can allow access to critical data or complete access to all data managed by the product. The CVSS 3.1 vector shows an attacker local physical (AV:A) with low attack complexity (AC:L), no privileges (PR:N), no user interaction (UI:N) and a scope change (S:C), yielding a high confidentiality impact (C:H) while integrity and availability remain unaffected.
Affected Systems
Oracle Agile Product Lifecycle Management for Process version 6.2.4 is the only confirmed vulnerable release. The advisory notes that compromising the installation component could affect other Oracle products, but only this version is verified as vulnerable at present.
Risk and Exploitability
The EPSS score of less than 1% indicates a low current probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS 3.1 Base Score of 7.4 reflects a significant confidentiality impact and a scope change that could extend the damage to other components of the product. Physical access remains a prerequisite, so on‑premises or shared‑facility environments where such access can be obtained may still face substantial risk despite the low EPSS score.
OpenCVE Enrichment