Impact
Oracle Agile PLM 9.3.6 contains a flaw in the Folders, Files & Attachments component that allows an unauthenticated attacker who can reach the HTTP interface to bypass normal access controls. The vulnerability is a classic information exposure (CWE‑200). An attacker must trick a user other than themselves into interacting with a specially crafted artifact; once that interaction occurs, the attacker can read any critical data stored in the system or gain full access to all data that the user is able to see. The flaw increases the confidentiality impact, as stated in the CVSS 3.1 vector, and does not affect integrity or availability.
Affected Systems
The only version explicitly listed as impacted is Oracle Agile PLM 9.3.6. All installations of that version, regardless of deployment environment, should be considered at risk.
Risk and Exploitability
The CVSS base score of 6.5 represents a medium severity risk. An EPSS score of less than 1% indicates that, as of now, automated exploitation is unlikely; however, the need for human interaction means that social‑engineering attempts may still be employed. The issue is not included in the CISA KEV catalog, further suggesting that widespread exploitation has not been documented. Exploitation would require an attacker to hold HTTP network access to the target instance and to entice a user into opening a malicious attachment or link that triggers the vulnerability.
OpenCVE Enrichment