Impact
The vulnerability is an authentication failure flaw in the Security component of Oracle Agile PLM 9.3.6 that allows an unauthenticated attacker with network access over HTTP to potentially compromise the application. Successful exploitation requires human interaction from a user other than the attacker, after which the attacker can gain full control of the system, reading, modifying, or deleting data and disrupting availability.
Affected Systems
Oracle Agile PLM 9.3.6, supplied by Oracle Corporation and part of its Oracle Supply Chain solutions. The CVE specifically targets the Security component of this version; no other releases are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates a high‑severity issue, with network access, low complexity, no privileges, and user interaction required. The EPSS score is below 1 % and the vulnerability is not in the CISA KEV catalog, suggesting a low probability of widespread exploitation. However, because the flaw can lead to full takeover of Oracle Agile PLM once user interaction occurs, organizations exposing Agile PLM to the public network face a significant risk and should act promptly.
OpenCVE Enrichment