Oracle Agile PLM Security Vulnerability
CVE-2017-10094

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
8 August 2017

Summary

A security vulnerability exists in Oracle Agile PLM within the Oracle Supply Chain Products Suite, affecting versions 9.3.5 and 9.3.6. This vulnerability can be exploited by a low privileged attacker who gains network access via HTTP, requiring human interaction for successful attacks. While it directly affects Oracle Agile PLM, the potential consequences can extend to other products as well. Exploitation may lead to unauthorized modifications to accessible data within Agile PLM, compromising both confidentiality and integrity of the data.

Affected Version(s)

Agile PLM Framework 9.3.5

Agile PLM Framework 9.3.6

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.