Impact
A vulnerability exists in the Event Java PX component of Oracle Agile PLM that permits a high‑privileged attacker with network access via the T3 or IIOP protocols to compromise the application. An attacker capable of authenticating with privileged credentials can execute arbitrary code, thereby taking full control of Oracle Agile PLM. Because the vulnerability changes scope, a successful exploit also threatens other related products. Confidentiality, integrity, and availability are all fully compromised.
Affected Systems
Oracle Agile PLM version 9.3.6 is affected. No other versions are listed as impacted at this time.
Risk and Exploitability
The CVSS 3.1 base score of 9.1 indicates critical severity, while the EPSS score of < 1% suggests that exploitation is rare at present and the vulnerability is not yet listed in CISA KEV. The attack vector is inferred to be remote, network‑based, and requires authentication of a privileged user to achieve full compromise via the T3 or IIOP protocols. The risk remains high for systems exposed to these networks, especially those with elevated privilege levels.
OpenCVE Enrichment