Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Install component of Oracle Agile Engineering Data Management version 6.2.1. A low privileged attacker who can reach the system over HTTP can exploit this flaw to create, delete or modify critical data without proper authorization, leading to loss of confidentiality and integrity. The description notes that successful attempts require the involvement of a user other than the attacker, indicating that the flaw may rely on user interaction or social engineering to complete the attack sequence.

Affected Systems

Affected systems are Oracle's Agile Engineering Data Management, specifically the 6.2.1 release from Oracle Corporation. The susceptible component is the Install module. No other product versions are listed as impacted.

Risk and Exploitability

The CVSS 3.1 base score of 6.4 indicates a medium severity vulnerability. The EPSS score is below 1%, suggesting a very low current exploitation probability. The flaw is not listed in CISA's KEV catalog, and the attack vector relies on HTTP network access, requiring low privilege and user interaction. Exploitability remains low but possible in environments where internal users can access the system or an attacker can influence a user session.

Generated by OpenCVE AI on August 4, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor's patch or upgrade to a newer version of Oracle Agile Engineering Data Management that addresses the Install component flaw.
  • Limit HTTP access to the application by configuring firewall rules or VPN to allow only trusted IP addresses.
  • Enable detailed auditing of data creation, deletion, and modification actions and regularly review user privileges to detect abnormal activity.

Generated by OpenCVE AI on August 4, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Attack Enables Unauthorized Data Modification in Oracle Agile Engineering Data Management

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title HTTP-Based Data Modification via User Interaction in Oracle Agile Engineering Data Management 6.2.1

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title HTTP-Based Data Modification via User Interaction in Oracle Agile Engineering Data Management 6.2.1

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low privilege HTTP exploitation in Oracle Agile Engineering Data Management

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low privilege HTTP exploitation in Oracle Agile Engineering Data Management
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:56.546Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61190

cve-icon Vulnrichment

Updated: 2026-07-23T15:19:01.073Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:15:03Z

Weaknesses