Impact
The flaw resides in the Security component of Oracle Agile PLM. An unauthenticated attacker who reaches the application over HTTP can create, delete, or modify critical data, resulting in unauthorized data manipulation and loss of confidentiality and integrity.
Affected Systems
Oracle Agile PLM from Oracle Corporation, version 9.3.6.
Risk and Exploitability
The CVSS 3.1 base score of 7.4 indicates high severity, with complete confidentiality and integrity impacts. The EPSS score of <1% suggests exploitation is currently rare. The vulnerability is not listed in CISA KEV. Attack requires only network access to HTTP, no prior authentication, making it difficult to exploit if the service is exposed to untrusted networks.
OpenCVE Enrichment