Executive brief
Oracle Agile PLM is a product lifecycle management system used by enterprises to manage product data and supply chain operations. An attacker with physical access to the network segment where the application server runs can bypass authentication and gain unauthorized access to create, modify, or delete critical product and supply chain data. This could enable competitors to steal product information, disrupt manufacturing schedules, or corrupt supplier records.
Technical details
This is an authentication bypass vulnerability in the Oracle Agile PLM application server (version 9.3.6) that requires adjacent network access and difficult exploitation conditions. The vulnerability allows an unauthenticated attacker positioned on the same physical network segment (adjacent attack vector) to compromise the application server without authentication. Successful exploitation grants unauthorized read and write access to all data managed by Agile PLM, including confidential product designs and supply chain records. The CVSS 3.1 score of 6.8 reflects high confidentiality and integrity impact but no availability impact. Patch status from Oracle is not yet confirmed based on available advisory details.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-09-15: disclosed