Impact
Oracle Agile PLM version 9.3.6 contains a flaw in its PGC/Excel Plugin that enables a low‑privileged network attacker to create, delete, or modify critical data without requiring user interaction. Successful exploitation can also cause the application to hang or repeatedly crash, resulting in a complete denial of service. The weakness is identified as a CWE‑284 (Improper Access Control).
Affected Systems
Oracle Agile PLM 9.3.6, specifically the PGC/Excel Plugin component, is the affected product. No other versions or components are known to contain this issue.
Risk and Exploitability
The vulnerability carries a CVSS base score of 8.1, indicating high severity with significant integrity and availability impacts. The EPSS score is less than 1%, hinting at a low but nonzero exploitation probability. Though not listed in the CISA KEV catalog, the lack of a KEV status does not mitigate the risk, especially given the critical supply‑chain data handled by Oracle Agile PLM. Attackers can exploit the flaw through network‑based HTTP requests from any remote location, requiring only low privileges and no user interaction.
OpenCVE Enrichment