CVE-2025-21560

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21560 is a vulnerability affecting the Oracle Agile PLM Framework product of Oracle Supply Chain, specifically the Software Development Kit (SDK) in version 9.3.6. This issue allows a low-privileged attacker with network access via HTTP to compromise the Oracle Agile PLM Framework. A successful attack can result in unauthorized access to critical data, granting the attacker complete access to all Oracle Agile PLM Framework accessible data. The vulnerability has a CVSS 3.1 Base Score of 6.5, with potential impacts on confidentiality.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle Agile Product Lifecycle Management Framework

Affected Vendors

  • BonqDAO