Cyber Resilience

CVE-2023-22039

Oracle Agile Plm 9.3.6

Published
18 July 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 5.4
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score 0.0036 28th percentile
Risk Priority 41 floored blend · peak EPSS

Summary

CVE-2023-22039 is a medium-severity an unspecified weakness vulnerability in Oracle Agile Plm. Its CVSS base score is 5.4 (Medium).

Operationally, ranked at the 28th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: WebClient). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks…

more

require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).

CWE(s)

Related Threats

CVEs Like This One

CVE-2026-61173Same product: Oracle Agile Plm
CVE-2026-61170Same product: Oracle Agile Plm
CVE-2026-61168Same product: Oracle Agile Plm
CVE-2026-61172Same product: Oracle Agile Plm
CVE-2026-61167Same product: Oracle Agile Plm
CVE-2026-61171Same product: Oracle Agile Plm
CVE-2026-61169Same product: Oracle Agile Plm
CVE-2026-46859Same product: Oracle Agile Plm
CVE-2026-61166Same product: Oracle Agile Plm
CVE-2019-2725Same product: Oracle Agile Plm

Affected Assets

oracle
agile plm
9.3.6

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References