Impact
Oracle Agile PLM 9.3.6 is affected by a high‑severity vulnerability in its security component that can be triggered over HTTP without authentication. The flaw permits attackers to compromise the application, effectively allowing full takeover. The impact spans confidentiality, integrity, and availability, with a CVSS base score of 9.8.
Affected Systems
Oracle Corporation’s Agile PLM product, version 9.3.6, is the only impacted release identified in the advisory.
Risk and Exploitability
The CVSS score of 9.8 indicates that exploitation would give an attacker almost complete control over the system. The vulnerability is easily exploitable, requiring only an unauthenticated network connection to the HTTP interface. An EPSS score of < 1% is reported, indicating that the probability of exploitation is very low but nonzero, yet the severity warrants immediate attention. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment