Executive brief
A critical vulnerability exists in Oracle's supply chain management software used to manage product quality and lifecycles. An unauthenticated attacker can remotely access the system over the network to view, modify, or delete sensitive corporate data. This could lead to a total loss of data integrity and confidentiality within the affected quality management component.
Technical details
This vulnerability affects the Product Quality Management component of Oracle Agile Product Lifecycle Management for Process, version 6.2.4. It is classified as easily exploitable, requiring no authentication or user interaction (AV:N/AC:L/PR:N/UI:N). An attacker can exploit this flaw via HTTP to compromise the application, leading to high impacts on confidentiality and integrity. While the specific CWE is not detailed in the advisory, the impact allows for unauthorized creation, deletion, or modification of all accessible data. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Agile Product Lifecycle Management for Process 6.2.4
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD