Vulnerability in Oracle Agile PLM Security Component
CVE-2017-10080
6.1MEDIUM
Summary
A vulnerability exists in the Oracle Agile PLM component of the Oracle Supply Chain Products Suite that allows an unauthenticated attacker with HTTP network access to compromise the system. This risk is exacerbated as successful exploitation requires user interaction by someone other than the attacker. Although the vulnerability specifically targets Oracle Agile PLM, it has the potential to adversely affect associated products. Attackers may gain unauthorized capabilities to update, insert, or delete data within Oracle Agile PLM, alongside unauthorized read access to certain datasets within the system.
Affected Version(s)
Agile PLM Framework 9.3.5
Agile PLM Framework 9.3.6
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved