Impact
A flaw in the Gantt Chart component of Oracle Agile PLM allows a low‑privileged user who can log onto the underlying infrastructure to compromise the entire application. Successful exploitation results in a full takeover of Oracle Agile PLM, compromising confidentiality, integrity, and availability as reflected in the CVSS 7.0 score. The vulnerability is considered difficult to exploit, but the impact is severe once activated.
Affected Systems
Oracle Corporation’s Agile PLM product, version 9.3.6, is the only version impacted. The attack vector involves the Gantt Chart module that processes user‑specifiable data within the application.
Risk and Exploitability
The CVSS vector (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates a moderate‑to‑high severity local exploit that requires only low privileged access. The EPSS score of 0.00109 indicates a very low probability of exploitation, yet the absence of an entry in the CISA KEV catalog suggests that no widespread exploitation has been reported yet. Nonetheless, the potential for complete system compromise warrants prompt attention.
OpenCVE Enrichment