Impact
Oracle Agile PLM 9.3.6 has an unauthenticated network vulnerability that can be exploited via HTTP requests without any authentication. Successful exploitation can give an attacker full control of the application, enabling disclosure of confidential data, tampering with operational data, and denial of service. The flaw is classified as an unauthorized access and authentication weakness (CWE‑284 and CWE‑306) and carries a CVSS 3.1 Base Score of 9.8, indicating complete loss of confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Oracle Corporation’s Agile PLM product version 9.3.6. No other versions or products are listed as impacted by the current CNA data.
Risk and Exploitability
The CVSS vector indicates an attacker with network access can exploit the flaw easily (low attack complexity, no user interaction). The EPSS score of less than 1% shows a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog. However, the high severity combined with the lack of authentication requirements means that exposed instances are at high risk of immediate exploitation if the system is reachable over the network.
OpenCVE Enrichment