CVE-2026-47009Medium· 6.5▾ SunlitVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with netw…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
0.4% → 0.4%
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).
agile_product_lifecycle_management = 9.3.6Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-22016High· 7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)
CVE-2026-87209High· 7.1Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security)
CVE-2025-30758Medium· 5.3Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: User Interface)
CVE-2026-46859Critical· 9.8Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security)
CVE-2023-22039Medium· 5.4Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient)
CVE-2022-21467Medium· 6.5Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Attachments)