Impact
A local privilege escalation flaw exists in the installation component of Oracle Product Lifecycle Analytics that allows an attacker with host access to fully compromise the application. The vulnerability has the potential to compromise confidentiality, integrity, and availability of the product and, because the vulnerability also impacts other associated Oracle Supply Chain products, it can lead to broader system compromise.
Affected Systems
Oracle Corporation’s Oracle Product Lifecycle Analytics, specifically version 3.6.1, is the affected release. No other product versions are listed as vulnerable.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 classifies this as a high‑severity issue. The EPSS score is below 1%, indicating a low but non‑zero probability of exploitation, while the lack of a KEV listing does not diminish the potential damage. The local attack vector combined with low privilege requirements makes the exploit highly feasible in environments where host access is not strictly controlled, and the scope change allows the compromise to spill over to related products.
OpenCVE Enrichment