Impact
This vulnerability in Oracle Agile PLM 9.3.6’s Web Client allows an unauthenticated attacker with HTTP network access to modify or read protected data. The flaw enables insertion, updating, or deletion of records and retrieval of information that should be inaccessible, creating confidentiality and integrity breaches. It stems from inadequate access control (CWE‑284).
Affected Systems
The only affected product is Oracle Agile PLM 9.3.6, specifically its Web Client component. No other versions or products are listed as impacted by this vulnerability.
Risk and Exploitability
The CVSS base score of 6.1 indicates low‑to‑medium severity with scope change, meaning compromised privilege can extend beyond the original scope. The EPSS value of less than 1% suggests that broad exploitation is unlikely at present, and the flaw is not in the CISA KEV catalog. Nonetheless, because the attack vector requires only an HTTP connection and the flaw permits unauthorized data modification and read, any instance exposed to a network, even through VPN or firewalls, remains at risk until a vendor fix is applied or the endpoint is tightly secured.
OpenCVE Enrichment