Oracle Agile PLM Vulnerability in Supply Chain Products Suite
CVE-2018-2609

6.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2018

Summary

A security vulnerability exists in the Oracle Agile PLM component of Oracle Supply Chain Products Suite that allows unauthenticated attackers with network access via HTTP to compromise the system. Successful exploitation requires the involvement of a user other than the attacker, which can lead to unauthorized updates, insertions, or deletions of accessible data. Additionally, it may allow unauthorized reading of specific data subsets within the Oracle Agile PLM environment, highlighting serious implications for data integrity and confidentiality.

Affected Version(s)

Agile PLM Framework 9.3.5

Agile PLM Framework 9.3.6

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.