Sceawere
Vulnerability Detail
CVE-2026-61175Updated Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Product Lifecycle Analytics Compromise
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.3
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Product Lifecycle Analytics
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues). The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics. While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.3 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.3",
"pubDate": "2026-07-21T22:18:49.290Z",
"pubdate": "2026-07-21T22:18:49.290Z",
"executiveSummary": "This vulnerability affects Oracle Product Lifecycle Analytics, specifically within the Installation Issues component, and impacts version 3.6.1.\nThe security flaw enables an unauthenticated, remote attacker to gain unauthorized access to critical data and induce a partial denial of service (DoS) against the system.\nBecause the vulnerability involves a scope change, successful exploitation may extend the impact beyond the target product to compromise additional integrated Oracle systems.\nThe vulnerability is characterized by high exploitability due to the lack of required authentication, low complexity, and the ability to trigger the attack remotely over HTTP.\nWith a CVSS 3.1 base score of 9.3, this flaw poses a critical risk to data confidentiality and availability, necessitating immediate attention to prevent unauthorized data exfiltration or service disruption.",
"technicalDetails": "The vulnerability resides within the Installation Issues component of Oracle Product Lifecycle Analytics version 3.6.1. It represents a critical security flaw that allows for unauthenticated remote access via HTTP protocols.\nThe root cause is likely an insecure configuration or flaw in the installation/deployment scripts or administrative endpoints, which fails to enforce access controls. This permits an attacker to interact with sensitive components without valid credentials or network-level authentication.\nThe attack flow begins with an attacker identifying the reachable HTTP interface of the Oracle Product Lifecycle Analytics installation. Given the 'Network access' and 'Attack Complexity: Low' parameters, the attacker can leverage standard HTTP requests to interact with the vulnerable component.\nOnce the initial connection is established, the scope change (S:C) indicates that the vulnerability allows an attacker to interact with the underlying host or adjacent system services. This escalation is particularly dangerous as it permits an attacker to perform operations outside the typical boundaries of the Oracle Product Lifecycle Analytics environment.\nExploitation leads to the unauthorized extraction of sensitive information (Confidentiality impact: High). Furthermore, the attacker can manipulate system resources or trigger anomalous states, leading to a partial denial of service (Availability impact: Low).\nBecause no user interaction (UI:N) is required and privileges (PR:N) are unnecessary, an automated script or a simple web client can be used to scan for and exploit this vulnerability at scale across the network. The ability to compromise data within the target product and potentially influence the integrity of related products highlights a significant failure in the security architecture of the affected version's deployment configuration.\nPost-exploitation, the attacker maintains the ability to exfiltrate critical business data stored within the Product Lifecycle Analytics instance or degrade service performance, causing operational downtime."
}