Impact
The Oracle Agile PLM 9.3.6 product contains a flaw in its security component that enables unauthenticated attackers who can reach the application via HTTP to bypass authorization controls and retrieve protected data. This bypass directly compromises confidentiality, allowing reading of any data accessible to the application, while integrity and availability remain unaffected. The vulnerability is identified as an authorization bypass (CWE-284).
Affected Systems
Oracle Corporation’s Agile PLM product, version 9.3.6, is the only version currently known to be affected. No other versions or related products are listed in the advisory.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 reflects high confidentiality impact with a low attack complexity, no privileges, and no user interaction, and an attack vector over the network via HTTP. The EPSS score of less than 1 % indicates a low likelihood of exploitation at present. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack path involves sending a crafted HTTP request to the vulnerable endpoint from an unauthenticated network host, causing the application to grant unauthorized access to protected data. The weakness is an authorization bypass (CWE-284).
OpenCVE Enrichment