Vulnerability in Oracle Agile PLM Component of Oracle Supply Chain Products
CVE-2017-10052
6.1MEDIUM
Summary
The vulnerability in the Oracle Agile PLM component of the Oracle Supply Chain Products Suite (subcomponent: PCMServlet) allows an unauthenticated attacker with network access via HTTP to compromise the Oracle Agile PLM system. Exploitation requires human interaction from a third party, and though the vulnerability is specific to Oracle Agile PLM, its impact may extend to other related products. Successful exploitation may result in unauthorized updates, inserts, or deletions of data, as well as unauthorized read access to certain data within Oracle Agile PLM. This poses significant risks to data confidentiality and integrity.
Affected Version(s)
Agile PLM Framework 9.3.5
Agile PLM Framework 9.3.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved