Executive brief
Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a security vulnerability in its core security component. An attacker who already has basic access to the server where the software is running can exploit this flaw to gain unauthorized access to sensitive business data. This could lead to a significant breach of proprietary product information and potentially impact other integrated systems.
Technical details
A vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. It is classified as an information disclosure issue that allows a low-privileged attacker with local logon access to the underlying infrastructure to compromise the application. The exploit is characterized by a 'scope change' (S:C), meaning the impact can extend beyond the Agile PLM environment to other integrated systems. The primary impact is on confidentiality, potentially resulting in complete access to all data accessible by the PLM software. The vulnerability is easily exploitable once local access is established. Patching information is typically found in the Oracle Critical Patch Update (CPU) for July 2026.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed