Impact
A flaw in the Install component of Oracle Agile Engineering Data Management allows a local, low‑privileged attacker who has logon access to the underlying infrastructure to compromise the application, potentially gaining full access to all data stored within the system; the vulnerability is exploitable with simplicity and can lead to the disclosure of sensitive information. The weakness is classified as CWE‑284 (Access Control Vulnerability).
Affected Systems
Oracle Corporation’s Agile Engineering Data Management version 6.2.1 is affected; the product is part of Oracle’s Supply Chain suite and the vulnerability may also impact other products exposed through the same installation due to a scope change.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity with a focus on confidentiality loss; the EPSS score is less than 1 %, showing a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local logon with low privileges, after which an attacker can use the vulnerability to bypass normal access controls and read any data accessible within the application. The attack vector is local, and an attacker would need to execute the exploitation from within the host serving the application. Furthermore, since the vulnerability involves a scope change, exploitation could potentially affect additional products or components within the same installation.
OpenCVE Enrichment