cbcvebase.

Oracle Agile Product Lifecycle Management vulnerabilities

56 known vulnerabilities affecting oracle/agile_product_lifecycle_management.

Total CVEs
56
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH16MEDIUM34LOW4

Vulnerabilities

Page 2 of 3
CVE-2016-3537P3MEDIUMCVSS 6.5v9.3.4v9.3.52016-07-21
CVE-2016-3537 [MEDIUM] CVE-2016-3537: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to File Folders / Attachment, a different vulnerability than CVE-2016-5473.
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1v9.3.32018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2016-5521P4MEDIUMCVSS 6.5v9.3.4v9.3.52016-10-25
CVE-2016-5521 [MEDIUM] CVE-2016-5521: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5512.
nvd
CVE-2016-3529P4MEDIUMCVSS 5.8v9.3.4v9.3.52016-07-21
CVE-2016-3529 [MEDIUM] CVE-2016-3529: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via vectors related to SDK, a different vulnerability than CVE-2016-3526 and CVE-2016-3560.
nvd
CVE-2016-5527P4MEDIUMCVSS 5.9v9.3.4v9.3.52016-10-25
CVE-2016-5527 [MEDIUM] CVE-2016-5527: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5524.
nvd
CVE-2016-3420P4MEDIUMCVSS 6.4v9.3.1.1v9.3.1.2+2 more2016-04-21
CVE-2016-3420 [MEDIUM] CVE-2016-3420: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3431.
nvd
CVE-2016-3431P4MEDIUMCVSS 6.4v9.3.1.1v9.3.1.2+2 more2016-04-21
CVE-2016-3431 [MEDIUM] CVE-2016-3431: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3420.
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8v9.3.3v9.3.5+1 more2020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2016-3555P4MEDIUMCVSS 6.1v9.3.4v9.3.52016-07-21
CVE-2016-3555 [MEDIUM] CVE-2016-3555: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via vectors related to PGC / Excel Plugin.
nvd
CVE-2016-3519P4MEDIUMCVSS 6.1v9.3.4v9.3.52016-07-21
CVE-2016-3519 [MEDIUM] CVE-2016-3519: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via vectors related to PC / Get Shortcut.
nvd
CVE-2016-3557P4MEDIUMCVSS 6.1v9.3.4v9.3.52016-07-21
CVE-2016-3557 [MEDIUM] CVE-2016-3557: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via vectors related to File Load.
nvd
CVE-2016-3560P4MEDIUMCVSS 5.3v9.3.4v9.3.52016-07-21
CVE-2016-3560 [MEDIUM] CVE-2016-3560: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via vectors related to SDK, a different vulnerability than CVE-2016-3526 and CVE-2016-3529.
nvd
CVE-2017-10093P4MEDIUMCVSS 5.3v9.3.5v9.3.62017-08-08
CVE-2017-10093 [MEDIUM] CWE-200 CVE-2017-10093: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in
nvd
CVE-2016-5524P4MEDIUMCVSS 5.3v9.3.4v9.3.52016-10-25
CVE-2016-5524 [MEDIUM] CWE-200 CVE-2016-5524: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5527.
nvd
CVE-2017-10052P4MEDIUMCVSS 6.1v9.3.5v9.3.62017-08-08
CVE-2017-10052 [MEDIUM] CVE-2017-10052: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: PCMServlet). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person ot
nvd
CVE-2017-10092P4MEDIUMCVSS 6.1v9.3.5v9.3.62017-08-08
CVE-2017-10092 [MEDIUM] CVE-2017-10092: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person othe
nvd
CVE-2017-10080P4MEDIUMCVSS 6.1v9.3.5v9.3.62017-08-08
CVE-2017-10080 [MEDIUM] CVE-2017-10080: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person othe
nvd
CVE-2017-10082P4MEDIUMCVSS 6.1v9.3.5v9.3.62017-08-08
CVE-2017-10082 [MEDIUM] CVE-2017-10082: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person othe
nvd
CVE-2016-3553P4MEDIUMCVSS 5.4v9.3.4v9.3.52016-07-21
CVE-2016-3553 [MEDIUM] CVE-2016-3553: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality and integrity via vectors related to PC Core.
nvd
CVE-2016-5510P4MEDIUMCVSS 5.3v9.3.4v9.3.52016-10-25
CVE-2016-5510 [MEDIUM] CWE-200 CVE-2016-5510: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9. Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors.
nvd