Impact
A flaw in Oracle Agile PLM’s Folders, Files & Attachments component allows a low‑privileged attacker with network access over HTTP to compromise the entire application. Successful exploitation can result in full control of the PLM system, compromising confidentiality, integrity, and availability of all managed data.
Affected Systems
Oracle Agile PLM 9.3.6 is affected. This version of the product, part of Oracle Supply Chain, is the only one listed with the issue; newer releases have not been reported as impacted.
Risk and Exploitability
The CVSS v3.1 Base Score of 7.5 reflects a high impact to all security properties, while the attack vector of network access and the low privilege requirement suggest that an attacker does not need advanced expertise, only connectivity. The EPSS score of less than 1% indicates that active exploitation has been low, and the vulnerability is not listed in the CISA KEV catalog. Likely, the attack path involves sending crafted HTTP requests to the vulnerable component from a compromised or malicious host, bypassing normal authorization checks and leading to takeover.
OpenCVE Enrichment