CVE-2026-21969
BaseFortify
Publication date: 2026-01-20
Last updated on: 2026-01-29
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | agile_product_lifecycle_management_for_process | 6.2.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Oracle Agile Product Lifecycle Management for Process product, specifically in the Supplier Portal component. It affects version 6.2.4 and allows an unauthenticated attacker with network access via HTTP to exploit it easily. Successful exploitation can lead to a complete takeover of the Oracle Agile Product Lifecycle Management for Process system.
How can this vulnerability impact me? :
The impact of this vulnerability is severe, as it can result in the attacker gaining full control over the Oracle Agile Product Lifecycle Management for Process system. This includes compromising confidentiality, integrity, and availability of the system, potentially leading to data breaches, unauthorized modifications, and service disruptions.