Executive brief
Oracle Agile PLM is a supply chain management and product lifecycle tool used by enterprises to manage product data and workflows. An unauthenticated attacker can exploit a security vulnerability via network access to achieve full compromise of the system, including data theft, modification, and system unavailability, though successful exploitation requires tricking a user into interacting with the attack.
Technical details
This is an easily exploitable vulnerability in the Oracle Agile PLM Security component affecting version 9.3.6. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system. The attack requires human interaction (a user clicking a malicious link or accepting a request), but does not require elevated privileges. Successful exploitation can result in complete system compromise with high impact on confidentiality, integrity, and availability. The vendor has been notified and patches are expected.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-08-18: disclosed