Impact
A vulnerability in Oracle Agile Engineering Data Management version 6.2.1 allows an attacker who has high privileged access to the underlying infrastructure to compromise the product. The flaw requires a separate person to interact with the system, enabling the attacker to gain full control and compromise confidentiality, integrity, and availability. The flaw is a missing authorization issue (CWE‑306). The vulnerability is rated CVSS 3.1 base 6.3 (Confidentiality, Integrity, Availability high). Successful exploitation can lead to a complete takeover of the application.
Affected Systems
Oracle Corporation’s Agile Engineering Data Management product, specifically version 6.2.1.
Risk and Exploitability
The attack vector is local with high privilege, meaning the attacker must already have administrative access to the host where the product runs. Because the exploit requires human interaction from another user, the probability of uncontrolled exploitation remains moderate, and the EPSS score indicates a very low but nonzero exploitation probability (< 1%). The Vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Thus, while the potential impact is severe, the likelihood of exploitation remains constrained to environments with unmanaged privileged accounts and exposed interfaces.
OpenCVE Enrichment