Impact
A network‑based vulnerability in Oracle Agile PLM version 9.3.6 allows attackers who do not possess privileged credentials to compromise the system. The flaw can be triggered by sending crafted HTTP requests to the application server, resulting in a takeover of the application and full control over its data, effectively compromising confidentiality, integrity, and availability. This weakness is reflected by CWE‑284, an authorization flaw that permits objects to be accessed by unauthorized users.
Affected Systems
Oracle Agile PLM release 9.3.6 is the only affected version according to the vendor alert. Systems that expose the application server to the network are at risk; no other versions or components are listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact risk, and the relatively low EPSS score of less than 1% suggests that exploitation in the wild is unlikely at present. The vulnerability is not catalogued in CISA KEV. To exploit the flaw, an attacker only needs low privilege and low attack complexity, sending crafted HTTP requests to the vulnerable component. Successful exploitation would allow the attacker to take full control of Oracle Agile PLM 9.3.6.
OpenCVE Enrichment