Executive brief
Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a security vulnerability in its core security component. An unauthorized attacker could exploit this flaw over the network to gain full control of the application. A successful compromise would allow the attacker to access sensitive product data, disrupt operations, and compromise the integrity of the supply chain management system.
Technical details
A vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw allows an unauthenticated attacker to achieve a full compromise (Confidentiality, Integrity, and Availability) of the system via the HTTP protocol. While the attack vector is network-based and requires no user interaction or privileges, Oracle classifies the exploit complexity as 'High,' suggesting specific environmental conditions or timing may be required for a successful attack. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory