Executive brief
Oracle Agile PLM, a software suite used for managing product lifecycles and supply chain data, contains a security vulnerability in its security component. An unauthenticated attacker could exploit this flaw over the network to gain unauthorized access to sensitive corporate data. If successful, the attacker could view, modify, or delete critical product information, potentially disrupting manufacturing processes and compromising intellectual property.
Technical details
A vulnerability exists in the Security component of Oracle Agile PLM version 9.3.6. The flaw allows an unauthenticated attacker with network access via HTTP to compromise the application. While the vulnerability is classified as difficult to exploit (Attack Complexity: High), a successful exploit grants the attacker unauthorized capabilities to create, delete, or modify all data accessible to the PLM system, as well as full read access to that data. The impact is limited to Confidentiality and Integrity, with no reported impact on Availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD