Impact
A low‑privileged attacker who can reach the system over a network TCP connection can trigger a fault that causes Oracle Agile Engineering Data Management to hang or crash repeatedly, resulting in a denial of service. The vulnerability does not affect confidentiality or integrity and there is no possibility of remote code execution or privilege escalation directly through the component.
Affected Systems
Oracle Corporation’s Oracle Agile Engineering Data Management product, version 6.2.1, is affected. The vulnerability resides in the Core component of Oracle Supply Chain software.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity focused on availability, with a low attack complexity and low privileges required. The EPSS score being less than 1% shows that exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. An attacker only needs network access to the vulnerable port and does not require UI interaction, allowing automated or scripted attacks. If exploited, the result is a complete denial of service until the product is restarted or the fault is otherwise mitigated.
OpenCVE Enrichment