Impact
A flaw in Oracle Agile PLM 9.3.6 permits an attacker with physical access to the host’s communication segment to create, delete, or alter critical data without authentication. The vulnerability is an example of improper access control (CWE‑284) and represents an authorization bypass, resulting in loss of confidentiality and integrity of all data accessible through Oracle Agile PLM.
Affected Systems
Oracle Corporation’s Agile PLM, version 9.3.6. No other versions are listed as affected.
Risk and Exploitability
The CVSS 3.1 score of 6.8 indicates moderate severity with high confidentiality and integrity impact. The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is physical access to the host’s communication segment, meaning remote exploitation over a network is not supported. The vulnerability requires only physical proximity; environments lacking a secured instrumentation network may see higher risk. The attacker can bypass authentication entirely, making it a serious threat for on‑premises deployments that are not isolated.
OpenCVE Enrichment