Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Agile Engineering Data Management 6.2.1 allows an attacker with low privileges and network connectivity over TCP to trigger a hang or repeated crash of the application. The flaw results in a complete loss of availability while there is no impact on confidentiality or integrity. It is a classic denial‑of‑service weakness that can be exploited by sending specially crafted network traffic to the exposed service.

Affected Systems

Oracle Agile Engineering Data Management version 6.2.1, the core component of Oracle Supply Chain’s Agile Engineering Data Management product suite. No other versions or variants are listed as affected.

Risk and Exploitability

The attack requires only simple TCP access and does not need authentication or elevated privileges. Because the EPSS score is below one percent and the vulnerability is not in CISA’s KEV catalog, the likelihood of widespread exploitation is low. The CVSS base score of 6.5 indicates moderate severity for availability, and an attacker can cause repeated crashes that disrupt business operations.

Generated by OpenCVE AI on August 13, 2026 at 11:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a fixed release that resolves the resource‑exhaustion weakness identified as CWE‑400.
  • If a patch is not yet available, limit inbound TCP traffic to the application using firewall rules and enforce input size validation to mitigate the resource‑exhaustion flaw (CWE‑400).
  • Implement monitoring of system resource utilization and automatically restart the application if abnormal usage patterns indicating a denial‑of‑service attack are detected.

Generated by OpenCVE AI on August 13, 2026 at 11:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Network‑Based Resource Exhaustion Leading to Denial of Service in Oracle Agile Engineering Data Management

Wed, 12 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Network TCP in Oracle Agile Engineering Data Management Core
Weaknesses CWE-399

Wed, 05 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Network TCP in Oracle Agile Engineering Data Management Core
Weaknesses CWE-399

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Network Exploitation in Oracle Agile Engineering Data Management
Weaknesses CWE-399
CWE-476

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Network Exploitation in Oracle Agile Engineering Data Management
Weaknesses CWE-399
CWE-476

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Application Crash in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-399

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Application Crash in Oracle Agile Engineering Data Management 6.2.1
Weaknesses CWE-399

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:11:30.975Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61195

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:51.400

Modified: 2026-07-28T02:10:24.290

Link: CVE-2026-61195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:15:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption