Executive brief
A vulnerability exists in Oracle's supply chain management software, specifically within the component used for importing data. A high-privileged user with access to the underlying server can exploit this flaw to gain full control over the application. This could lead to a complete compromise of product lifecycle data, impacting the confidentiality and integrity of manufacturing and supply chain processes.
Technical details
This vulnerability affects the Data Import component of Oracle Agile Product Lifecycle Management for Process, version 6.2.4. It is classified as a local exploit, requiring the attacker to have existing high-privileged logon access to the infrastructure where the software is executing. The root cause allows for a complete compromise of the application's Confidentiality, Integrity, and Availability (CIA triad). Successful exploitation results in a total takeover of the Agile PLM for Process instance. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.
Affected products
- Oracle Agile Product Lifecycle Management for Process 6.2.4
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Published in Oracle Critical Patch Update