Impact
Oracle has identified a vulnerability in the Agile PLM SDK component that is active in version 9.3.6. An attacker with only low privileges and who can reach the system over HTTP can exploit the flaw to gain unauthorized access to data stored in Agile PLM. The flaw has the effect of exposing all data accessible through the platform, resulting in a confidentiality compromise, while integrity and availability remain largely untouched.
Affected Systems
The product affected is Oracle Agile PLM, part of Oracle Supply Chain, specifically version 9.3.6. Because the flaw lies in a core component, other products that rely on the same SDK could also be exposed, though the scope change indicates that additional product data may be impacted as well.
Risk and Exploitability
The CVSS Base Score of 7.7 signals a high confidentiality impact; the EPSS score of less than 1% points to a low likelihood of exploitation in the wild at present, and the vulnerability is not yet listed in the CISA KEV catalogue. Nonetheless, attackers that gain network access could launch the attack without any special privileges, making the risk real for any exposed instance. Organizations should treat the flaw as a significant threat until a patch is applied.
OpenCVE Enrichment