Impact
An authentication bypass exists in the Engineering Communication Interface that allows an attacker who can physically connect to the communication segment attached to the Oracle Agile Engineering Data Management hardware to send arbitrary commands without authentication. This is a CWE-284 Incorrect Access Control flaw. The flaw enables the attacker to execute any operation the system supports, effectively taking control of the application and the data it manages, which results in complete compromise of confidentiality, integrity and availability.
Affected Systems
The vulnerability affects Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain Management. Only this specific version is listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a moderate‑to‑high severity. EPSS score of < 1% indicates a very low probability of exploitation and the flaw is not in the CISA KEV catalog. The attack vector (AV:A) shows that an attacker must act from an adjacent physical segment, requiring high effort and no credentials. Once physical access is achieved, the attacker can fully take over the system, presenting a high risk especially for environments that expose the engineering communication interface. The lack of an immediate patch elevates the threat, though the necessity of physical proximity mitigates remote risk.
OpenCVE Enrichment