Executive brief
A critical vulnerability has been identified in Oracle's supply chain management software used for product lifecycle tracking. An unauthenticated attacker can remotely exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive product data, disruption of supply chain operations, and unauthorized modification of process records.
Technical details
This vulnerability exists within the Reporting component of Oracle Agile Product Lifecycle Management for Process (version 6.2.4). It is classified as an easily exploitable flaw that requires no user interaction or prior authentication. An attacker can exploit this vulnerability by sending specially crafted HTTP requests over the network. A successful exploit results in a complete takeover of the application, impacting the confidentiality, integrity, and availability of the entire system. Oracle has addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Agile Product Lifecycle Management for Process 6.2.4
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory