Oracle Agile Product Lifecycle Management vulnerabilities
56 known vulnerabilities affecting oracle/agile_product_lifecycle_management.
Total CVEs
56
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH16MEDIUM34LOW4
Vulnerabilities
Page 3 of 3
CVE-2019-2817P4MEDIUMCVSS 5.4v9.3.3v9.3.4+2 more2019-07-23
CVE-2019-2817 [MEDIUM] CVE-2019-2817: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Folders, Files & Attachments). Supported versions that are affected are 9.3.3, 9.3.4, 9.3.5 and 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require hum
nvd
CVE-2020-2920P4MEDIUMCVSS 6.1v9.3.3v9.3.5+1 more2020-04-15
CVE-2020-2920 [MEDIUM] CVE-2020-2920: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). Supporte
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). Supported versions that are affected are 9.3.3, 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the atta
nvd
CVE-2016-5512P4MEDIUMCVSS 6.1v9.3.4v9.3.52016-10-25
CVE-2016-5512 [MEDIUM] CWE-79 CVE-2016-5512: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5521.
nvd
CVE-2018-2609P4MEDIUMCVSS 6.1v9.3.5v9.3.62018-01-18
CVE-2018-2609 [MEDIUM] CVE-2018-2609: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other
nvd
CVE-2021-41165P4MEDIUMCVSS 5.4v9.3.62021-11-17
CVE-2021-41165 [MEDIUM] CWE-79 CVE-2021-41165: CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discov
CKEditor4 is an open source WYSIWYG HTML editor. In affected version a vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed comments HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users usi
nvd
CVE-2016-3509P4MEDIUMCVSS 5.4v9.3.4v9.3.52016-07-21
CVE-2016-3509 [MEDIUM] CVE-2016-3509: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Folders / URL Attachment.
nvd
CVE-2017-10094P4MEDIUMCVSS 5.4v9.3.5v9.3.62017-08-08
CVE-2017-10094 [MEDIUM] CWE-269 CVE-2017-10094: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a pers
nvd
CVE-2016-3517P4MEDIUMCVSS 4.3v9.3.4v9.3.52016-07-21
CVE-2016-3517 [MEDIUM] CVE-2016-3517: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect integrity via vectors related to PC / Get Shortcut.
nvd
CVE-2016-3507P4MEDIUMCVSS 4.3v9.3.4v9.3.52016-07-21
CVE-2016-3507 [MEDIUM] CVE-2016-3507: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect integrity via vectors related to WebClient / Admin.
nvd
CVE-2016-5513P4MEDIUMCVSS 4.3v9.3.4v9.3.52016-10-25
CVE-2016-5513 [MEDIUM] CWE-200 CVE-2016-5513: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to File Manager.
nvd
CVE-2016-5522P4MEDIUMCVSS 4.3v9.3.4v9.3.52016-10-25
CVE-2016-5522 [MEDIUM] CWE-200 CVE-2016-5522: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-2017-10299P4MEDIUMCVSS 4.3v9.3.5v9.3.62017-10-19
CVE-2017-10299 [MEDIUM] CWE-200 CVE-2017-10299: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in u
nvd
CVE-2016-3531P4LOWCVSS 3.5v9.3.4v9.3.52016-07-21
CVE-2016-3531 [LOW] CVE-2016-3531: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to PC / Notification.
nvd
CVE-2016-5473P4LOWCVSS 3.1v9.3.4v9.3.52016-07-21
CVE-2016-5473 [LOW] CVE-2016-5473: Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality via vectors related to File Folders / Attachment, a different vulnerability than CVE-2016-3537.
nvd
CVE-2017-10308P4LOWCVSS 3.5v9.3.5v9.3.62017-10-19
CVE-2017-10308 [LOW] CVE-2017-10308: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Performance). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows physical access to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access t
nvd
CVE-2017-10088P4LOWCVSS 3.4v9.3.5v9.3.62017-08-08
CVE-2017-10088 [LOW] CVE-2017-10088: Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent:
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM executes to compromise Oracle Agile PLM. Successful attacks of this vul
nvd
← Previous3 / 3