Oracle Agile Product Lifecycle Management For Process vulnerabilities

13 known vulnerabilities affecting oracle/agile_product_lifecycle_management_for_process.

Total CVEs
13
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH3MEDIUM8LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-21969CRITICALCVSS 9.8v6.2.42026-01-20
CVE-2026-21969 [CRITICAL] CVE-2026-21969: Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Successful
nvd
CVE-2026-21944MEDIUMCVSS 6.8v6.2.42026-01-20
CVE-2026-21944 [MEDIUM] CWE-79 CVE-2026-21944: Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Proc
nvd
CVE-2024-21092HIGHCVSS 8.1v6.2.4.22024-04-16
CVE-2024-21092 [HIGH] CVE-2024-21092: Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Su
nvd
CVE-2024-21091MEDIUMCVSS 6.5v6.2.4.22024-04-16
CVE-2024-21091 [MEDIUM] CWE-284 CVE-2024-21091: Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Success
nvd
CVE-2024-20956HIGHCVSS 7.3fixed in 6.2.4.22024-02-17
CVE-2024-20956 [HIGH] CVE-2024-20956: Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Installation). Supported versions that are affected are Prior to 6.2.4.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process. Success
nvd
CVE-2021-2351HIGHCVSS 7.5v6.2.2.0v6.2.3.02021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-11022MEDIUMCVSS 6.1ExploitedPoCv6.2.0.02020-04-29
CVE-2020-11022 [MEDIUM] CWE-79 CVE-2020-11022: In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted source In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2019-11358MEDIUMCVSS 6.1ExploitedPoCv6.1v6.2.0.0+3 more2019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2018-3134MEDIUMCVSS 5.0v6.2.0.02018-10-17
CVE-2018-3134 [MEDIUM] CVE-2018-3134: Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Suppl Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Supply Chain Products Suite (subcomponent: User Group Management). The supported version that is affected is 6.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Product Lifecycle Management f
nvd
CVE-2018-3069LOWCVSS 2.7v6.2.0.02018-07-18
CVE-2018-3069 [LOW] CVE-2018-3069: Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Suppl Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Supply Chain Products Suite (subcomponent: Installation). The supported version that is affected is 6.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Proces
nvd
CVE-2018-2572MEDIUMCVSS 6.1v6.1.1.6v6.2.0.0+1 more2018-04-19
CVE-2018-2572 [MEDIUM] CVE-2018-2572: Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Suppl Vulnerability in the Oracle Agile Product Lifecycle Management for Process component of Oracle Supply Chain Products Suite (subcomponent: Installation). Supported versions that are affected are 6.1.1.6, 6.2.0.0 and 6.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycl
nvd
CVE-2015-9251MEDIUMCVSS 6.1v6.2.0.0v6.2.1.0+3 more2018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2016-5504MEDIUMCVSS 4.1v6.1.0.4v6.1.1.6+1 more2016-10-25
CVE-2016-5504 [MEDIUM] CWE-200 CVE-2016-5504: Unspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Unspecified vulnerability in the Oracle Agile Product Lifecycle Management for Process component in Oracle Supply Chain Products Suite 6.1.0.4, 6.1.1.6, and 6.2.0.0 allows local users to affect confidentiality via vectors related to Supplier Portal.
nvd