Impact
An exploitable flaw exists in the Security component of Oracle Agile PLM 9.3.6. The weakness involves insufficient privilege checks and access controls (CWE-269, CWE-284, CWE-287, and CWE-306), allowing a low‑privileged attacker who can reach the server over HTTP to compromise the application, resulting in a complete takeover that exposes the system’s data and control functions. The impact includes total loss of confidentiality, integrity, and availability as indicated by the CVSS Base Score of 8.8.
Affected Systems
Oracle Corporation’s Oracle Agile PLM product, version 9.3.6, is affected. The weakness is within the Security component of the application.
Risk and Exploitability
The CVSS v3.1 Base Score of 8.8 indicates the vulnerability is exploitable over the network with low attacker privileges and no user interaction. The EPSS score of less than 1% suggests exploitation is currently considered uncommon, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is HTTP network access, where an attacker can inject malformed requests to trigger the bug and gain full control of the application.
OpenCVE Enrichment