Impact
A flaw in the installation component of Oracle Product Lifecycle Analytics allows a low‑privileged attacker who can reach the system over HTTP to gain full control of the application.
Affected Systems
Oracle Product Lifecycle Analytics version 3.6.1, part of Oracle Supply Chain’s Product Lifecycle Analytics suite.
Risk and Exploitability
The CVSS base score of 7.5 indicates moderate to high severity, while the EPSS score of less than 1% shows a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, but because it can be triggered remotely over an open HTTP port with no user interaction, attackers can potentially compromise the system if they can reach the vulnerable endpoint.
OpenCVE Enrichment