Impact
The vulnerability allows an attacker without authentication to exploit the HTTP interface of Oracle Product Lifecycle Analytics 3.6.1. The flaw is an authentication bypass that can be triggered from any network location that can reach the service, permitting a full takeover of the application. Successful exploitation would result in a complete loss of confidentiality, integrity, and availability of the service, effectively granting the attacker remote code execution capabilities (inferred). The weakness maps to CWE‑287 (Authentication Bypass) and CWE‑306 (Missing Authentication for Continuous Access).
Affected Systems
The affected product is Oracle Corporation’s Product Lifecycle Analytics version 3.6.1, a component of Oracle Supply Chain. This is the only supported version listed as vulnerable. The product runs on an HTTP interface that is accessible to unauthenticated users, and the vulnerability is tied to the Core component of the application.
Risk and Exploitability
The CVSS v3.1 score of 9.8 indicates critical severity for confidentiality, integrity, and availability. The EPSS score is less than 1 %, implying a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the attack vector is simple – it requires only network access to the risk significant for exposed instances. Administrators should treat this as a high‑priority issue and prioritize remediation.
OpenCVE Enrichment