Impact
The vulnerability allows a high privileged attacker who can reach the system over Oracle Net to create, delete, or modify critical data within Oracle Product Lifecycle Analytics. The impact includes unauthorized access to all data accessible by the product and the potential for complete loss of confidentiality and integrity as listed in the CVSS vector. The weakness is consistent with a flaw in access control mechanisms.
Affected Systems
Oracle Corporation’s Oracle Product Lifecycle Analytics, specifically version 3.6.1.
Risk and Exploitability
The CVSS 3.1 base score of 8.7 indicates a high severity with confidentiality and integrity impacts. The EPSS score of < 1% suggests a very low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers with network access and high privileges can exploit the flaw by connecting to Oracle Net, achieving elevated privileges and modifying or deleting data, thereby changing the scope of the vulnerability.
OpenCVE Enrichment