Executive brief
A critical vulnerability exists in Oracle's Agile Product Lifecycle Management (PLM) for Process, a software suite used by manufacturers to manage product development and supply chain data. An unauthenticated attacker can exploit this flaw over a network to gain full control of the system. This could lead to the theft of sensitive intellectual property, disruption of manufacturing processes, and unauthorized changes to product specifications.
Technical details
A critical vulnerability exists in the Installation component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. The flaw is characterized by a low attack complexity and requires no user interaction or prior authentication. An attacker can exploit this vulnerability remotely via TCP to achieve a complete compromise of the application, impacting confidentiality, integrity, and availability. Successful exploitation allows for a total takeover of the PLM environment. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Agile Product Lifecycle Management for Process 6.2.4
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD.