Oracle Agile Product Lifecycle Management vulnerabilities
56 known vulnerabilities affecting oracle/agile_product_lifecycle_management.
Total CVEs
56
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH16MEDIUM34LOW4
Vulnerabilities
Page 1 of 3
CVE-2025-21556CRITICALCVSS 9.9v9.3.62025-01-21
CVE-2025-21556 [CRITICAL] CWE-863 CVE-2025-21556: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Int
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PL
nvd
CVE-2025-21565HIGHCVSS 7.5v9.3.62025-01-21
CVE-2025-21565 [HIGH] CWE-863 CVE-2025-21565: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install).
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2025-21564HIGHCVSS 8.1v9.3.62025-01-21
CVE-2025-21564 [HIGH] CWE-732 CVE-2025-21564: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Int
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can resu
nvd
CVE-2025-21560MEDIUMCVSS 6.5v9.3.62025-01-21
CVE-2025-21560 [MEDIUM] CWE-863 CVE-2025-21560: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Softw
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can
nvd
CVE-2024-21287HIGHCVSS 7.5KEVv9.3.62024-11-18
CVE-2024-21287 [HIGH] CWE-863 CVE-2024-21287: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulne
nvd
CVE-2024-20953HIGHCVSS 8.8KEVv9.3.62024-02-17
CVE-2024-20953 [HIGH] CWE-502 CVE-2024-20953: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supp
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS
nvd
CVE-2021-41165MEDIUMCVSS 5.4v9.3.62021-11-17
CVE-2021-41165 [HIGH] CWE-79 CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discov
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using
nvd
CVE-2020-2920MEDIUMCVSS 6.1v9.3.3v9.3.5+1 more2020-04-15
CVE-2020-2920 [MEDIUM] CVE-2020-2920: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). Supporte
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). Supported versions that are affected are 9.3.3, 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the atta
nvd
CVE-2020-1935MEDIUMCVSS 4.8v9.3.3v9.3.5+1 more2020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2019-2817MEDIUMCVSS 5.4v9.3.3v9.3.4+2 more2019-07-23
CVE-2019-2817 [MEDIUM] CVE-2019-2817: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Folders, Files & Attachments). Supported versions that are affected are 9.3.3, 9.3.4, 9.3.5 and 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require hum
nvd
CVE-2019-0227HIGHCVSS 7.5PoCv9.3.32019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2018-8032MEDIUMCVSS 6.1v9.3.32018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2018-11040HIGHCVSS 7.5v9.3.3v9.3.4+1 more2018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2018-1257MEDIUMCVSS 6.5v9.3.3v9.3.4+2 more2018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2018-2609MEDIUMCVSS 6.1v9.3.5v9.3.62018-01-18
CVE-2018-2609 [MEDIUM] CVE-2018-2609: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other
nvd
CVE-2017-10299MEDIUMCVSS 4.3v9.3.5v9.3.62017-10-19
CVE-2017-10299 [MEDIUM] CWE-200 CVE-2017-10299: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in u
nvd
CVE-2017-10308LOWCVSS 3.5v9.3.5v9.3.62017-10-19
CVE-2017-10308 [LOW] CVE-2017-10308: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Performance). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows physical access to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access t
nvd
CVE-2017-10052MEDIUMCVSS 6.1v9.3.5v9.3.62017-08-08
CVE-2017-10052 [MEDIUM] CVE-2017-10052: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PCMServlet). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person ot
nvd
CVE-2017-10092MEDIUMCVSS 6.1v9.3.5v9.3.62017-08-08
CVE-2017-10092 [MEDIUM] CVE-2017-10092: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person othe
nvd
CVE-2017-10080MEDIUMCVSS 6.1v9.3.5v9.3.62017-08-08
CVE-2017-10080 [MEDIUM] CVE-2017-10080: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person othe
nvd
1 / 3Next →