Impact
The vulnerability in Oracle Product Lifecycle Analytics 3.6.1 is an installation issue that permits a low‑privileged attacker who can reach the service over HTTP to compromise the application. Successful exploitation enables full takeover, giving the attacker control over data and application functions. The flaw is a privilege escalation and authorization check weakness identified as CWE‑269.
Affected Systems
Oracle Corporation’s Product Lifecycle Analytics version 3.6.1; all installations of this specific version are affected. The vulnerability is tied to the installation component of the product.
Risk and Exploitability
The CVSS base score of 7.5 highlights high confidentiality, integrity and availability impact. The EPSS score of less than 1% indicates a presently low likelihood of exploitation, but because the flaw permits takeover, it remains a serious risk. The vector is network‑based via the HTTP interface and requires only low privilege, with no user interaction. Attack complexity is high due to difficulty to exploit, but a successful attack would provide attackers with full control.
OpenCVE Enrichment