CVE-2025-21556: Buffer Overflow
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PLM Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-21556?
CVE-2025-21556 is categorized as an easily exploitable vulnerability with potential significant impact.
How do I fix CVE-2025-21556?
To fix CVE-2025-21556, update your Oracle Agile PLM Framework to the latest version provided by Oracle.
Who is affected by CVE-2025-21556?
Organizations using Oracle Agile PLM Framework version 9.3.6 are specifically affected by CVE-2025-21556.
What types of attacks can exploit CVE-2025-21556?
CVE-2025-21556 can be exploited by low privileged attackers with network access via HTTP.
What component of Oracle is impacted by CVE-2025-21556?
CVE-2025-21556 impacts the Agile Integration Services component of the Oracle Agile PLM Framework.