Executive brief
Oracle Agile PLM is a product lifecycle management system used to manage product design, development, and compliance data across supply chains. This vulnerability in the Web Client allows an unauthenticated attacker to conduct cross-site scripting (XSS) attacks that trick users into compromising the system, potentially exposing or modifying sensitive product data and manufacturing information.
Technical details
This is a reflected or stored cross-site scripting (XSS) vulnerability in the Oracle Agile PLM Web Client component. The vulnerability is easily exploitable and requires no authentication, but does require user interaction—typically when an attacker tricks a user into clicking a malicious link. The attack is delivered via HTTP and exploits a lack of input validation or output encoding in the Web Client. Successful exploitation allows an attacker to read, modify, or delete data accessible through the victim's session, with potential scope change affecting other Oracle Supply Chain products. Patches are available from Oracle; users should apply the latest updates to version 9.3.6 or later.
Affected products
- Oracle Agile PLM 9.3.6
Timeline
- 2026-09-15: disclosed