Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).
Published: 2026-07-21
Score: 2.8 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Install component of Oracle Agile Engineering Data Management 6.2.1 permits a local user with low privileges to trigger a partial loss of availability. The vulnerability requires the cooperation of a separate user; it does not grant additional privileges or compromise other parts of the system. When exploited, the application becomes temporarily unresponsive, reflecting the availability impact captured in the CVSS vector.

Affected Systems

The target product is Oracle AGILE Engineering Data Management from Oracle Corporation, specifically version 6.2.1. No other versions are listed as affected in the CNA data.

Risk and Exploitability

The CVSS score of 2.8 signifies a low‑severity availability risk, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The issue is not listed in CISA's KEV catalog, suggesting no known widespread attacks. The attack vector is local; an attacker must have low‑privileged logon to the host running the product and rely on another user to initiate the installation component activity. There is no evidence of remote exploitation or privilege escalation.

Generated by OpenCVE AI on August 2, 2026 at 19:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Agile Engineering Data Management update that addresses the Install component issue or install the vendor‑supplied patch.
  • Limit local logon privileges to trusted administrators, ensuring the Install component cannot be invoked by non‑essential users.
  • Monitor application logs and system metrics for repeated failures or resource exhaustion that may indicate attempted exploitation of the denial‑of‑service flaw.

Generated by OpenCVE AI on August 2, 2026 at 19:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Install Component in Oracle Agile Engineering Data Management

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local Denial of Service via Install Component in Oracle Agile Engineering Data Management

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Local Low-Privilege Denial of Service via Install Component in Oracle Agile Engineering Data Management
Weaknesses CWE-388
CWE-400

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Low-Privilege Denial of Service via Install Component in Oracle Agile Engineering Data Management
Weaknesses CWE-388
CWE-400

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-404
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:22:16.988Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61187

cve-icon Vulnrichment

Updated: 2026-07-23T15:22:12.520Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T19:45:06Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release