Impact
An attacker with low privilege who can reach the application over HTTP can exploit a flaw in the installation component of Oracle Agile Product Lifecycle Management for Process to compromise the entire system. The vulnerability allows the attacker to gain control of the application, potentially leading to full takeover. The CVSS 3.1 base score of 7.5 indicates significant impacts on confidentiality, integrity, and availability.
Affected Systems
The affected system is Oracle Agile Product Lifecycle Management for Process version 6.2.4 as supplied by Oracle Corporation. No other versions are mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 7.5 reflects a high severity risk, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is a remote exploitation of the installation component via HTTP traffic, requiring only network access and low‑privilege credentials.
OpenCVE Enrichment