Impact
Vulnerability in the Install component of Oracle Agile Engineering Data Management 6.2.1 that permits an unauthenticated attacker with network access via HTTP to create, delete, or modify critical data, read restricted data, or cause a full system hang or crash. The weakness results in confidentiality, integrity, and availability impacts as reflected in the CVSS vector, and it capitalizes on improper access control safeguards.
Affected Systems
Oracle Corporation’s Oracle Agile Engineering Data Management 6.2.1 is affected. The product is part of Oracle Supply Chain and operates over HTTP endpoints enabled by the Install component. No other versions are listed in the CNA data.
Risk and Exploitability
The CVSS base score of 9.4 indicates a high severity vulnerability, while the EPSS score of less than 1% shows a currently low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is unauthenticated HTTP network traffic to the exposed Install service. Successful exploitation would grant the attacker unrestricted data modification rights and the ability to induce a denial‑of‑service condition, impacting all users of the affected instance.
OpenCVE Enrichment