Executive brief
Oracle Agile Product Lifecycle Management (PLM) for Process, a software suite used by manufacturers to manage product development and supply chain data, contains a security vulnerability in its installation component. A remote attacker with low-level user credentials could exploit this flaw to gain full control over the application. A successful compromise could lead to the theft of sensitive product intellectual property, disruption of manufacturing workflows, or unauthorized changes to product specifications.
Technical details
A vulnerability exists in the Installation component of Oracle Agile Product Lifecycle Management for Process version 6.2.4. The flaw is classified as difficult to exploit (High Attack Complexity) but can be triggered by a low-privileged attacker with network access via HTTP. Successful exploitation allows for a complete compromise of the application, impacting confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026. Security engineers should apply the relevant patches from Oracle to mitigate the risk of full system takeover.
Affected products
- Oracle Agile Product Lifecycle Management for Process 6.2.4
Timeline
- 2026-07-21: disclosed: Published via Oracle Critical Patch Update and NVD.