Impact
Oracle Agile PLM 9.3.6 contains a flaw that permits an unauthenticated attacker to interact with the application over HTTP. By exploiting this weakness, the attacker can obtain unrestricted access to confidential data stored within the system and, in some cases, cause a partial denial of service. The vulnerability is rooted in improper access control and authentication handling (CWE‑284).
Affected Systems
The affected product is Oracle Agile PLM version 9.3.6, a component of Oracle Supply Chain Management. No other versions or vendors are listed.
Risk and Exploitability
The CVSS v3.1 base score of 8.2 reflects significant confidentiality loss with some availability impact. The EPSS score of less than 1% indicates that the exploit rate is currently very low, though the vulnerability is not yet cataloged in CISA’s KEV list. The likely attack vector is network‑based; the flaw can be triggered via any HTTP traffic to the vulnerable application server, making it easily exploitable by remote actors with network access.
OpenCVE Enrichment