cbcvebase.

Oracle Agile Product Lifecycle Management vulnerabilities

56 known vulnerabilities affecting oracle/agile_product_lifecycle_management.

Total CVEs
56
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH16MEDIUM34LOW4

Vulnerabilities

Page 1 of 3
CVE-2024-20953P1HIGHCVSS 8.8KEVv9.3.62024-02-17
CVE-2024-20953 [HIGH] CWE-502 CVE-2024-20953: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supp Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3
nvd
CVE-2024-21287P1HIGHCVSS 7.5KEVv9.3.62024-11-18
CVE-2024-21287 [HIGH] CWE-863 CVE-2024-21287: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulne
nvd
CVE-2019-0227P2HIGHCVSS 7.5PoCv9.3.32019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2025-21556P3CRITICALCVSS 9.9v9.3.62025-01-21
CVE-2025-21556 [CRITICAL] CWE-863 CVE-2025-21556: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Int Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PL
nvd
CVE-2016-3556P3CRITICALCVSS 9.8v9.3.4v9.3.52016-07-21
CVE-2016-3556 [CRITICAL] CVE-2016-3556: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to EM Integration.
nvd
CVE-2016-3554P3HIGHCVSS 8.8v9.3.4v9.3.52016-07-21
CVE-2016-3554 [HIGH] CVE-2016-3554: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to PC / BOM, MCAD, and Design.
nvd
CVE-2016-5523P3HIGHCVSS 8.8v9.3.4v9.3.52016-10-25
CVE-2016-5523 [HIGH] CVE-2016-5523: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AutoVue Java Applet.
nvd
CVE-2016-5515P3HIGHCVSS 8.8v9.3.4v9.3.52016-10-25
CVE-2016-5515 [HIGH] CVE-2016-5515: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to RMIServlet.
nvd
CVE-2016-5514P3HIGHCVSS 8.8v9.3.4v9.3.52016-10-25
CVE-2016-5514 [HIGH] CVE-2016-5514: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to ExportServlet.
nvd
CVE-2018-11040P3HIGHCVSS 7.5v9.3.3v9.3.4+1 more2018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2025-21564P3HIGHCVSS 8.1v9.3.62025-01-21
CVE-2025-21564 [HIGH] CWE-732 CVE-2025-21564: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Int Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can resu
nvd
CVE-2025-21565P3HIGHCVSS 7.5v9.3.62025-01-21
CVE-2025-21565 [HIGH] CWE-863 CVE-2025-21565: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2016-3526P3HIGHCVSS 7.5v9.3.4v9.3.52016-07-21
CVE-2016-3526 [HIGH] CVE-2016-3526: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via vectors related to SDK, a different vulnerability than CVE-2016-3529 and CVE-2016-3560.
nvd
CVE-2016-3561P3HIGHCVSS 7.3v9.3.4v9.3.52016-07-21
CVE-2016-3561 [HIGH] CVE-2016-3561: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to SDK.
nvd
CVE-2016-5526P3HIGHCVSS 7.3v9.3.4v9.3.52016-10-25
CVE-2016-5526 [HIGH] CWE-284 CVE-2016-5526: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apache Tomcat.
nvd
CVE-2025-21560P3MEDIUMCVSS 6.5v9.3.62025-01-21
CVE-2025-21560 [MEDIUM] CWE-863 CVE-2025-21560: Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Softw Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can
nvd
CVE-2016-3538P3HIGHCVSS 7.1v9.3.4v9.3.52016-07-21
CVE-2016-3538 [HIGH] CVE-2016-3538: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect integrity and availability via vectors related to File Folders / Attachment, a different vulnerability than CVE-2016-3539.
nvd
CVE-2016-3539P3HIGHCVSS 7.1v9.3.4v9.3.52016-07-21
CVE-2016-3539 [HIGH] CVE-2016-3539: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect integrity and availability via vectors related to File Folders / Attachment, a different vulnerability than CVE-2016-3538.
nvd
CVE-2016-3530P3HIGHCVSS 7.1v9.3.4v9.3.52016-07-21
CVE-2016-3530 [HIGH] CVE-2016-3530: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect integrity and availability via vectors related to PGC / Import.
nvd
CVE-2018-1257P3MEDIUMCVSS 6.5v9.3.3v9.3.4+2 more2018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd