Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-07-21
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Agile Engineering Data Management permits a low‑privileged attacker who has logged onto the host infrastructure to perform unauthorized updates, inserts, or deletions of data within the document management component, and to trigger a partial denial of service. The flaw is caused by improper access controls that allow privileged actions without proper authorization, leading to loss of data integrity and reduced availability.

Affected Systems

The affected product is Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain’s document management component. Only this specific release is listed by the CNA as vulnerable; no other versions are mentioned.

Risk and Exploitability

The CVSS base score of 4.4 indicates a moderate risk with low confidentiality impact but small integrity and availability effects. The EPSS score is below 1%, showing that the likelihood of real‑world exploitation is currently very low. The flaw is not listed in CISA’s KEV catalog. Successful exploitation requires the attacker to have local logon rights on the infrastructure hosting the application; remote exploitation is not possible. Although the impact is limited, patching is still advisable to eliminate the permissive access control fully.

Generated by OpenCVE AI on August 5, 2026 at 01:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Oracle Agile Engineering Data Management 6.2.1 from Oracle’s support site. Must be used as the primary remediation.
  • Restrict local logon privileges on servers hosting the application to the minimum permissions required for normal operation, preventing local accounts from performing administrative functions within the application.
  • Review and enforce server‑level access controls to ensure that local accounts cannot elevate privileges inside the application.

Generated by OpenCVE AI on August 5, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low-privilege Access Control Failure Allows Unauthorized Data Modification and Partial Denial of Service
Weaknesses CWE-284
CWE-285

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service via Improper Access Controls
Weaknesses CWE-284

Sat, 01 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service via Improper Access Controls
Weaknesses CWE-284

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low Privilege Attack in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-284

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification and Partial Denial of Service via Low Privilege Attack in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 4.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:18:23.809Z

Reserved: 2026-07-08T15:52:20.739Z

Link: CVE-2026-61191

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses