CVE-2025-21556

Published Jan 21, 2025

Last updated 18 days ago

Overview

Description
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM Framework. While the vulnerability is in Oracle Agile PLM Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Source
secalert_us@oracle.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-863

Social media

Hype score
Not currently trending
  1. 2/8 CVE-2025-21556 in Agile PLM (CVSS 9.9) allows attackers to take control. Patch now to protect your systems. #CyberVulnerability #AgilePLM 🚨🔧

    @Eth1calHackrZ

    26 Jan 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🧵 CVE ID: CVE-2025-21556 🔴 Severity: CRITICAL 📜 Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged… ht

    @TyroneSoftware

    23 Jan 2025

    61 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨CVE Alert: Critical Oracle Agile PLM Framework Privilege Escalation Vulnerability🚨 Vulnerability Details: CVE-2025-21556 (CVSS 9.9/10) Oracle Agile PLM Framework Privilege Escalation Vulnerability Impact A Successful exploit may allow an attacker to takeover the Oracle Agile

    @CyberxtronTech

    23 Jan 2025

    81 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-21556 alert 🚨 Oracle: Critical vulnerability in Agile PLM Framework The vulnerability has been integrated into Patrowl. Our customers assets are protected. 🦉 #CyberSecurity #InfoSec #oracle https://t.co/jJSvXzhKgO

    @Patrowl_io

    22 Jan 2025

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Oracle has revealed 318 new security vulnerabilities in its January 2025 Critical Patch Update, including a critical flaw (CVE-2025-21556) with a 9.9 score that lets low-privilege attackers seize control of the Agile PLM Framework. Time to patch up! 🔒✨

    @eilonh1

    22 Jan 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. CVE-2025-21556 is a critical vulnerability in Oracle's Agile PLM Framework, specifically within the Agile Integration Services component. This flaw allows low-privileged attackers with network access via HTTP to potentially take over the affected system. https://t.co/BkDRRWnZX8

    @GrimmAnalyst

    22 Jan 2025

    70 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    2 Replies

    0 Quotes

  7. CVE-2025-21556 Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is affected is 9.… https://t.co/vhaOzsZHeN

    @CVEnew

    21 Jan 2025

    191 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. [CVE-2025-21556: CRITICAL] Oracle's Agile PLM Framework product from their Supply Chain faces a severe vulnerability allowing network-based attackers to compromise system integrity, with a CVSS score of 9.9.#cybersecurity,#vulnerability https://t.co/g9Yvkk94Xw https://t.co/wnDG80

    @CveFindCom

    21 Jan 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes