CVE-2025-21560
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 21, 2025
Summary
CVE-2025-21560 is a vulnerability affecting the Oracle Agile PLM Framework product of Oracle Supply Chain, specifically the Software Development Kit (SDK) in version 9.3.6. This issue allows a low-privileged attacker with network access via HTTP to compromise the Oracle Agile PLM Framework. A successful attack can result in unauthorized access to critical data, granting the attacker complete access to all Oracle Agile PLM Framework accessible data. The vulnerability has a CVSS 3.1 Base Score of 6.5, with potential impacts on confidentiality.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle Agile Product Lifecycle Management Framework
Affected Vendors
- BonqDAO