Impact
The flaw exists in the Application Server component of Oracle Agile PLM 9.3.6 and allows a low‑privileged attacker who can reach the system over HTTP to bypass authentication or authorization checks, gaining unauthorized read access to all data the application exposes. This results in a confidentiality breach but does not alter data integrity or availability.
Affected Systems
Oracle Agile PLM version 9.3.6 is the only explicitly vulnerable release. The CNA notes that the flaw’s impact scope can extend to additional Oracle supply‑chain products that rely on the same instance, potentially exposing a wider set of data if the same vulnerability is present.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 marks the issue as high severity, yet the EPSS score of less than 1 % indicates exploitation attempts are rare so far and the flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability over the network using plain HTTP and need only low‐privileged access, which simplifies the attack vector, but the confidentiality impact remains significant.
OpenCVE Enrichment