Impact
The vulnerability resides in the install component of Oracle Agile Engineering Data Management and allows an attacker with low privileges and network access over HTTP to trigger an application hang or frequent crash, fully denying service to legitimate users. The flaw results in a loss of availability while authentication and impact are limited to this component.
Affected Systems
Oracle Corporation’s Oracle Agile Engineering Data Management 6.2.1 is affected. No information regarding other versions is provided in the CVE data.
Risk and Exploitability
The CVSS vector AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H yields a Base Score of 5.3. The EPSS score is below 1 %, indicating very low current exploitation likelihood, and the vulnerability is not listed in CISA KEV. The likely attack path requires network connectivity to the application’s HTTP endpoint and minimal privileges; exploitation would disrupt availability but not confidentiality or integrity.
OpenCVE Enrichment