Impact
A flaw in Oracle Agile PLM 9.3.6 allows an attacker with network access over HTTP to create, delete or alter data without authentication. The vulnerability carries a CVSS 3.1 base score of 9.1, highlighting critical consequences for confidentiality and integrity. Successful exploitation would give an adversary the ability to change or remove any data handled by the application, effectively bypassing all built‑in access controls.
Affected Systems
Oracle Agile PLM 9.3.6 is the only version affected by this issue; the advisory specifies that the flaw exists solely in that release.
Risk and Exploitability
The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) indicates that the attack is network‑based, low in complexity, and requires no user interaction. The EPSS score of <1% conveys a low likelihood of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker merely needs to send crafted HTTP requests to the exposed service; no privilege elevation or special configuration is required. The root cause relates to improper access control, missing authentication checks, and potential insecure default settings.
OpenCVE Enrichment