Impact
A vulnerability exists in Oracle Product Lifecycle Analytics version 3.6.1 that allows an attacker with low privilege and network access over Oracle Net to gain unauthorized access to critical data and to insert, update or delete data. The impact includes confidentiality and integrity compromises, as reflected in the CVSS vector. The issue is flagged as an installation issue but the attack could extend to additional products, evidencing a scope change.
Affected Systems
The affected product is Oracle Product Lifecycle Analytics by Oracle Corporation, version 3.6.1. No other affected versions or products are listed in the available data.
Risk and Exploitability
The CVSS base score of 8.5 marks this as high severity. The EPSS score is less than 1%, indicating a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based via Oracle Net, and requires only low privilege to execute. Successful exploitation can allow an attacker to gain full access to all accessible data and alter or delete that data, potentially impacting additional products if the scope is expanded.
OpenCVE Enrichment