Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).
Published: 2026-07-21
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Install component of Oracle Agile Engineering Data Management 6.2.1 that permits an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data, read restricted data, or cause a full system hang or crash. The weakness results in confidentiality, integrity, and availability impacts as reflected in the CVSS vector, and it capitalizes on improper access control safeguards.

Affected Systems

Oracle Corporation’s Oracle Agile Engineering Data Management 6.2.1 is affected. The product is part of Oracle Supply Chain and operates over HTTP endpoints enabled by the Install component. No other versions are listed in the CNA data.

Risk and Exploitability

The CVSS base score of 9.4 indicates a high severity vulnerability, while the EPSS score of less than 1% shows a currently low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is unauthenticated HTTP network traffic to the exposed Install service. Successful exploitation would grant the attacker unrestricted data modification rights and the ability to induce a denial‑of‑service condition, impacting all users of the affected instance.

Generated by OpenCVE AI on August 4, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade Oracle Agile Engineering Data Management to a version that mitigates the vulnerability, following the guidance in the Oracle CPU Jul 2026 advisory.
  • Enforce strict network segmentation and firewall rules to allow the Install HTTP service only from trusted, minimal IP ranges, effectively limiting unauthenticated network reach.
  • Implement monitoring and alerting on unusual data modification or system crash events, and continually scan for unauthorized access attempts to the product.

Generated by OpenCVE AI on August 4, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Allows Data Tampering and Denial of Service in Oracle Agile Engineering Data Management

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Manipulation and Denial of Service in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-200

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
CWE-400
CWE-732
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Data Manipulation and Denial of Service in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-200
CWE-284

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Exploitation in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-284
CWE-285
CWE-306

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Access Exploitation in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-284
CWE-285
CWE-306

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized read access to a subset of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:52.694Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61186

cve-icon Vulnrichment

Updated: 2026-07-23T15:23:20.585Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-732

    Incorrect Permission Assignment for Critical Resource