CVE-2025-21556
published 2025-01-21CVE-2025-21556: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected…
PriorityP357critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
0.62%
45.6th percentile
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PLM Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | agile_product_lifecycle_management | — | — |
| oracle_corporation | oracle_agile_plm_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability affects Oracle Agile PLM Framework version 9.3.6, component: Agile Integration Services, exploitable by low-privileged authenticated attacker over HTTP with no user interaction required (CVSS 9.9, scope change) ↗
- →Monitor HTTP traffic to Oracle Agile PLM Framework (version 9.3.6) Agile Integration Services endpoints for anomalous low-privileged authenticated requests that may indicate exploitation attempts leading to full system takeover ↗
- ·Only Oracle Agile PLM Framework version 9.3.6 is confirmed affected; the vulnerability is specifically within the Agile Integration Services component and requires network access via HTTP with low privileges (PR:L) ↗
- ·Scope change is confirmed (S:C in CVSS vector), meaning successful exploitation can impact systems beyond the vulnerable Oracle Agile PLM Framework instance itself ↗
- ·Patch was released as part of Oracle Critical Patch Update January 2025; remediation requires applying the January 2025 CPU ↗
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_oracle9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Supply Chain Risk Matrix: Agile Integration Services — CVE-2025-21556
vendor_oracle·2025-01-15·CVSS 9.9
CVE-2025-21556 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Agile Integration Services — CVE-2025-21556
Oracle Oracle Supply Chain Risk Matrix: Agile Integration Services vulnerability
CVE: CVE-2025-21556
CVSS: 9.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
GHSA
GHSA-2hmh-wh7q-6wpr: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services)
ghsa_unreviewed·2025-01-21
CVE-2025-21556 [CRITICAL] CWE-863 GHSA-2hmh-wh7q-6wpr: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services)
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PLM Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-21
Published