Impact
A flaw in the Install component of Oracle Agile Engineering Data Management 6.2.1 permits a local user with low privileges to trigger a partial loss of availability. The vulnerability requires the cooperation of a separate user; it does not grant additional privileges or compromise other parts of the system. When exploited, the application becomes temporarily unresponsive, reflecting the availability impact captured in the CVSS vector.
Affected Systems
The target product is Oracle AGILE Engineering Data Management from Oracle Corporation, specifically version 6.2.1. No other versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS score of 2.8 signifies a low‑severity availability risk, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The issue is not listed in CISA's KEV catalog, suggesting no known widespread attacks. The attack vector is local; an attacker must have low‑privileged logon to the host running the product and rely on another user to initiate the installation component activity. There is no evidence of remote exploitation or privilege escalation.
OpenCVE Enrichment