Impact
The vulnerability occurs in Oracle Product Lifecycle Analytics version 3.6.1 and permits a low‑privileged network attacker with HTTP access to bypass normal access controls. The flaw can be leveraged to read confidential information, modify or delete data, and cause a partial denial of service. The weakness is a lack of proper authorization enforcement, enabling unauthorized actions that affect confidentiality, integrity, and availability.
Affected Systems
Affected systems are Oracle Supply Chain products specifically Product Lifecycle Analytics running the 3.6.1 release on any platform supported by the product. No other versions are listed as impacted; the vulnerability is limited to the 3.6.1 build.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high severity, and the vector shows that network access is sufficient to exploit with low privilege. The EPSS score of <1% (approximately 0.00323) indicates a very low but non‑zero probability of exploitation. The vulnerability is not currently listed in the CISA KEV catalog, but the potential impact of unauthorized data access and service disruption warrants immediate mitigation.
OpenCVE Enrichment