Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Install component of Oracle Agile Engineering Data Management allows a local, low‑privileged attacker who has logon access to the underlying infrastructure to compromise the application, potentially gaining full access to all data stored within the system; the vulnerability is exploitable with simplicity and can lead to the disclosure of sensitive information. The weakness is classified as CWE‑284 (Access Control Vulnerability).

Affected Systems

Oracle Corporation’s Agile Engineering Data Management version 6.2.1 is affected; the product is part of Oracle’s Supply Chain suite and the vulnerability may also impact other products exposed through the same installation due to a scope change.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a moderate severity with a focus on confidentiality loss; the EPSS score is less than 1 %, showing a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local logon with low privileges, after which an attacker can use the vulnerability to bypass normal access controls and read any data accessible within the application. The attack vector is local, and an attacker would need to execute the exploitation from within the host serving the application. Furthermore, since the vulnerability involves a scope change, exploitation could potentially affect additional products or components within the same installation.

Generated by OpenCVE AI on August 4, 2026 at 01:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security updates site for a patch or hotfix for Agile Engineering Data Management 6.2.1 and apply it immediately once available.
  • Reduce the set of local users with the ability to log into the host running the application to the minimum required for operational purposes.
  • Implement network segmentation to isolate the application environment from other critical infrastructure and monitor for unauthorized access attempts.

Generated by OpenCVE AI on August 4, 2026 at 01:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Local Access Control Vulnerability in Oracle Agile Engineering Data Management 6.2.1

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local Access Control Vulnerability in Oracle Agile Engineering Data Management 6.2.1

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Data Disclosure in Oracle Agile Engineering Data Management

Sun, 26 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Leading to Data Disclosure in Oracle Agile Engineering Data Management

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:55.750Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61189

cve-icon Vulnrichment

Updated: 2026-07-23T15:10:33.981Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses