Impact
Oracle Agile PLM version 9.3.6 contains a flaw in the Export component that lets a low‑privileged attacker reach the system over HTTP. Employing this vulnerability may grant the attacker full control of the application, jeopardizing confidentiality, integrity and availability. The weakness is classified as CWE‑284, representing an improper access control error.
Affected Systems
The affected product is Oracle Agile PLM, version 9.3.6, delivered through the Export component.
Risk and Exploitability
With an AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H vector the flaw is easily exploitable from the network, requiring only low privilege to achieve a complete takeover. The EPSS score of < 1% indicates a low probability of exploit, yet the high CVSS 3.1 base score of 8.8 signals severe potential impact. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment