Impact
A vulnerability in the Security component of Oracle Agile PLM version 9.3.6 allows a local, low‑privileged attacker who can log into the host to compromise the application. The flaw enables the attacker to take full control of the Agile PLM system, allowing unauthorized disclosure of confidential data, modification of business processes, and denial of service to users. The impact is total loss of confidentiality, integrity, and availability for the application.
Affected Systems
Oracle Agile PLM version 9.3.6 from Oracle Corporation. No other versions are listed as affected, though the description notes that successful exploitation could affect additional products integrated with Agile PLM due to the scope change.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation in the wild, yet the description states the exploit is easily achievable by a local user with low privileges. It is not listed in the CISA KEV catalog. The attack vector is local and requires an existing login, relying on the attacker’s ability to reach the host where Agile PLM runs.
OpenCVE Enrichment