Back to overview

CVE-2026-47009

MEDIUM
6.5
CVSS 3.1

Metadata

CVE ID
CVE-2026-47009
State
PUBLISHED
Assigner
oracle
Reserved
2026-05-18 15:55 UTC
Published
2026-07-21 21:33 UTC
Last updated
2026-07-29 03:55 UTC
Primary CWE
CWE-200
CWE-200 Exposure of Sensitive Information to an Unauthorized…
Vendor / Product
Oracle Corporation / Oracle Agile PLM
Sources
cve.org  ·  NVD

Severity & Metrics

6.5 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Oracle Corporation Oracle Agile PLM — 9.3.6
Weakness (CWE)
CWESourceDescription
— cna Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data.
CWE-200 adp CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.5 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Back to overview