First published: Tue Jan 21 2025(Updated: )
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PLM Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Agile Product Lifecycle Management Framework |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-21556 is categorized as an easily exploitable vulnerability with potential significant impact.
To fix CVE-2025-21556, update your Oracle Agile PLM Framework to the latest version provided by Oracle.
Organizations using Oracle Agile PLM Framework version 9.3.6 are specifically affected by CVE-2025-21556.
CVE-2025-21556 can be exploited by low privileged attackers with network access via HTTP.
CVE-2025-21556 impacts the Agile Integration Services component of the Oracle Agile PLM Framework.