Impact
The vulnerability is a local privilege escalation in the Engineering Communication Interface component of Oracle Agile Engineering Data Management. A low‑privileged user with logon access to the host can exploit a flaw that allows them to compromise the instance, potentially leading to loss of confidentiality, integrity, and availability.
Affected Systems
Oracle Agile Engineering Data Management version 6.2.1 from Oracle Corporation is affected. The product is part of Oracle Supply Chain’s Engineering Communication Interface component. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 7.0 indicates a high severity with full confidentiality, integrity, and availability impacts. EPSS score of < 1% indicates a low exploitation probability, and the flaw requires a low‑privileged user with logon access, limiting exploitation to local actors. The CVE states the vulnerability is difficult to exploit, and it is not listed in the CISA KEV catalog. The potential for complete application takeover warrants immediate attention, and the likely attack vector is local exploitation by a low‑privileged host user.
OpenCVE Enrichment