Impact
According to the CVE description, the Oracle Agile PLM 9.3.6 product contains a vulnerability that enables a low‑privileged attacker with network access via HTTP to compromise the application. The flaw is an improper access control weakness (CWE‑284) that can be exploited easily, giving an attacker the ability to take over the system. Successful exploitation would undermine confidentiality, integrity, and availability of the application, effectively allowing an attacker to control Oracle Agile PLM.
Affected Systems
The affected product is Oracle Agile PLM, version 9.3.6, part of the Oracle Supply Chain Management suite.
Risk and Exploitability
The vulnerability can be exploited over HTTP, giving a network attacker with low privileges the ability to compromise the application. The EPSS score is below 1 %, indicating a very low but non‑zero probability of widespread exploitation. While the vulnerability is not listed in the CISA KEV catalog, the CVSS v3.1 base score of 8.8 reflects a high‑impact risk for exposed installations where the User and User Group component is reachable over the network.
OpenCVE Enrichment