Impact
The vulnerability in Oracle Agile PLM 9.3.6 allows an attacker with plain HTTP network access, without prior authentication, to gain control of the application. Successful exploitation can lead to full takeover of the PLM instance, causing total loss of confidentiality, integrity, and availability of the system’s data. The weakness arises from improper access control in the security component, which permits bypassing authentication checks, enabling attackers to execute actions with the privileges of the application. This flaw corresponds to CWE‑284 (Improper Access Control) and CWE‑306 (Missing Authentication Material).
Affected Systems
Oracle Agile PLM version 9.3.6, deployed by Oracle Corporation, is affected.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity with complete confidentiality, integrity, and availability impact. The EPSS score of less than 1% suggests that, as of the latest data, exploitation has been rare, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need network connectivity to the PLM's HTTP port and no prior authentication. Although the exploitation path is difficult, the potential damage is catastrophic if the vulnerability is successfully leveraged.
OpenCVE Enrichment