PT-2015-2562 · Oracle · Oracle Agile Plm
Published
2015-10-21
·
Updated
2016-12-24
·
CVE-2015-4797
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Agile PLM version 9.3.3
Description
The issue is related to errors in the code of the Oracle Agile PLM component in Oracle Supply Chain Products Suite. It may allow a remote attacker to modify data, potentially affecting the integrity of the system. The vulnerability can be exploited by remote authenticated users via unknown vectors related to Security.
Recommendations
For Oracle Agile PLM version 9.3.3, consider restricting access to sensitive data and functionality until a patch or fix is available. As a temporary workaround, limit the privileges of remote authenticated users to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Agile Plm