Oracle agile plm framework
This hub aggregates every CVE we track for Oracle agile plm framework, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
1
Critical
7
High
1
In CISA KEV
Severity distribution
HIGH7MEDIUM2CRITICAL1
Monthly trend
0
0
1
0
4
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Oracle agile plm framework.
- CVE-2025-21565Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Install). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unaut...7.5
- CVE-2025-21564Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnera...8.1
- CVE-2025-21560Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: SDK-Software Development Kit). The supported version that is affected is 9.3.6. Easily exploitable vulne...6.5
- CVE-2025-21556Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnera...9.9
- CVE-2024-21287Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily ex...KEV7.5
- CVE-2021-40690Bypass of the secureValidation property7.5
- CVE-2019-10072The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UP...7.5
- CVE-2019-0227A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subve...7.5
- CVE-2018-15756DoS Attack via Range Requests7.5
- CVE-2018-8032Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.6.1
Product normalization is registry-driven with AI assist and human review. How it works