Impact
The vulnerability in Oracle Agile Engineering Data Management permits a low‑privileged attacker who has logged onto the host infrastructure to perform unauthorized updates, inserts, or deletions of data within the document management component, and to trigger a partial denial of service. The flaw is caused by improper access controls that allow privileged actions without proper authorization, leading to loss of data integrity and reduced availability.
Affected Systems
The affected product is Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain’s document management component. Only this specific release is listed by the CNA as vulnerable; no other versions are mentioned.
Risk and Exploitability
The CVSS base score of 4.4 indicates a moderate risk with low confidentiality impact but small integrity and availability effects. The EPSS score is below 1%, showing that the likelihood of real‑world exploitation is currently very low. The flaw is not listed in CISA’s KEV catalog. Successful exploitation requires the attacker to have local logon rights on the infrastructure hosting the application; remote exploitation is not possible. Although the impact is limited, patching is still advisable to eliminate the permissive access control fully.
OpenCVE Enrichment