Executive brief
Oracle Product Lifecycle Analytics is a supply chain management tool used to track and manage product lifecycles. A vulnerability in the installation component allows a low-privileged network attacker to gain full control over the system, potentially compromising sensitive supply chain data and disrupting product management operations.
Technical details
This is a difficult-to-exploit privilege escalation vulnerability affecting Oracle Product Lifecycle Analytics 3.6.1. The vulnerability exists in the installation component and requires a low-privileged user with network access via HTTP. Successful exploitation allows an attacker to achieve complete system compromise with high impact on confidentiality, integrity, and availability. The CVSS 3.1 vector (AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates the attack is network-accessible but requires high complexity and prior authentication. Patches or workarounds have not yet been publicly announced.
Affected products
- Oracle Product Lifecycle Analytics 3.6.1
Timeline
- 2026-09-15: disclosed: Published in Oracle security alert