Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker who can reach the system over a network TCP connection can trigger a fault that causes Oracle Agile Engineering Data Management to hang or crash repeatedly, resulting in a denial of service. The vulnerability does not affect confidentiality or integrity and there is no possibility of remote code execution or privilege escalation directly through the component.

Affected Systems

Oracle Corporation’s Oracle Agile Engineering Data Management product, version 6.2.1, is affected. The vulnerability resides in the Core component of Oracle Supply Chain software.

Risk and Exploitability

The CVSS 3.1 base score of 6.5 indicates a moderate severity focused on availability, with a low attack complexity and low privileges required. The EPSS score being less than 1% shows that exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. An attacker only needs network access to the vulnerable port and does not require UI interaction, allowing automated or scripted attacks. If exploited, the result is a complete denial of service until the product is restarted or the fault is otherwise mitigated.

Generated by OpenCVE AI on August 2, 2026 at 19:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for version 6.2.1 as soon as it becomes available
  • Restrict inbound TCP traffic to the product to only trusted hosts or IP ranges
  • Implement firewall or access‑control rules that log and alert on anomalous traffic patterns to the affected port

Generated by OpenCVE AI on August 2, 2026 at 19:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Network DoS via Low-Privileged Attack in Oracle Agile Engineering Data Management

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Network DoS via Low-Privileged Attack in Oracle Agile Engineering Data Management

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Oracle Agile Engineering Data Management Crash via Network Exploit
Weaknesses CWE-399

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Oracle Agile Engineering Data Management Crash via Network Exploit
Weaknesses CWE-399

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:15:49.527Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61194

cve-icon Vulnrichment

Updated: 2026-07-23T15:15:42.641Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T19:45:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption