Impact
Oracle Product Lifecycle Analytics version 3.6.1 has an installation issue that lets an attacker with low‑privilege access on the host create, modify, or delete critical data, and potentially gain full access to any data stored in the product. The flaw offers a direct route for privilege escalation, compromising confidentiality and integrity but not availability.
Affected Systems
The vulnerability affects Oracle Product Lifecycle Analytics 3.6.1, a component of Oracle Supply Chain. Because the flaw can alter the scope, other Oracle products running on the same infrastructure may also be exposed.
Risk and Exploitability
The CVSS score of 8.4 denotes high severity, while the EPSS score of less than 1 % suggests that exploitation is unlikely but not impossible. The vulnerability is exploitable from requires no network connectivity or special tooling. The flaw is not listed in the CISA KEV catalog, indicating no known widespread attacks so far. Nonetheless, the potential for unauthorized data creation, deletion, or modification makes it a critical risk for organizations that rely on Oracle Product Lifecycle Analytics.
OpenCVE Enrichment