Impact
This vulnerability resides in the Folders, Files & Attachments component of Oracle Agile PLM 9.3.6 and enables an attacker with low privileges to access, update, insert, or delete data that should be restricted. The resulting impact is a combination of confidentiality loss for critical data and integrity breaches, without affecting availability.
Affected Systems
Oracle Corporation’s Oracle Agile PLM version 9.3.6 is affected. Users of this product, particularly those who expose the application via HTTP and have low‑privilege accounts, are at risk.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. Attackers can exploit this weakness through HTTP traffic from the network and only need low privileges. However, the EPSS score is below 1% and the CISA KEV catalog, suggesting a low likelihood of widespread exploitation. Human interaction from a non‑attacker is required, which further reduces the ease of exploitation. The scope change mentioned in the description indicates that exploitation could potentially affect additional products within the supply chain ecosystem.
OpenCVE Enrichment