Impact
The vulnerability resides in the Install component of Oracle Agile Engineering Data Management version 6.2.1. A low privileged attacker who can reach the system over HTTP can exploit this flaw to create, delete or modify critical data without proper authorization, leading to loss of confidentiality and integrity. The description notes that successful attempts require the involvement of a user other than the attacker, indicating that the flaw may rely on user interaction or social engineering to complete the attack sequence.
Affected Systems
Affected systems are Oracle's Agile Engineering Data Management, specifically the 6.2.1 release from Oracle Corporation. The susceptible component is the Install module. No other product versions are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 6.4 indicates a medium severity vulnerability. The EPSS score is below 1%, suggesting a very low current exploitation probability. The flaw is not listed in CISA's KEV catalog, and the attack vector relies on HTTP network access, requiring low privilege and user interaction. Exploitability remains low but possible in environments where internal users can access the system or an attacker can influence a user session.
OpenCVE Enrichment