Impact
The vulnerability in Oracle Agile Engineering Data Management 6.2.1 allows an attacker with low privileges and network connectivity over TCP to trigger a hang or repeated crash of the application. The flaw results in a complete loss of availability while there is no impact on confidentiality or integrity. It is a classic denial‑of‑service weakness that can be exploited by sending specially crafted network traffic to the exposed service.
Affected Systems
Oracle Agile Engineering Data Management version 6.2.1, the core component of Oracle Supply Chain’s Agile Engineering Data Management product suite. No other versions or variants are listed as affected.
Risk and Exploitability
The attack requires only simple TCP access and does not need authentication or elevated privileges. Because the EPSS score is below one percent and the vulnerability is not in CISA’s KEV catalog, the likelihood of widespread exploitation is low. The CVSS base score of 6.5 indicates moderate severity for availability, and an attacker can cause repeated crashes that disrupt business operations.
OpenCVE Enrichment