Impact
A flaw in Oracle Agile PLM allows an unauthenticated attacker who can reach the system over HTTP to read data that should be protected. Because there is no authentication requirement before the request is processed, the attacker can read any information stored by the application, potentially gaining full visibility of all data accessible to the platform. The vulnerability directly compromises confidentiality, exposing critical or sensitive information to an unauthorized party.
Affected Systems
The affected product is Oracle Agile PLM, version 9.3.6 from Oracle Corporation. No other versions or products are listed as impacted.
Risk and Exploitability
The vulnerability is rated as CVSS 7.5, indicating a substantial risk to confidentiality with no impact on integrity or availability. The EPSS score is < 1 %, indicating a very low but non‑zero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based access via HTTP, and the exploitation is considered easily achievable because no credentials are required. This makes the flaw a significant concern for organizations that expose Oracle Agile PLM to external or even internal network traffic without additional safeguards.
OpenCVE Enrichment