Impact
Oracle Agile Engineering Data Management 6.2.1 contains an easily exploitable local vulnerability that permits a high-privileged attacker who can log onto the underlying infrastructure to compromise the application. The flaw allows complete takeover, impacting confidentiality, integrity, and availability. The vulnerability represents a privilege escalation or access control weakness.
Affected Systems
The affected product is Oracle Agile Engineering Data Management, version 6.2.1, part of Oracle Supply Chain. No other versions or components are listed as impacted.
Risk and Exploitability
The CVSS 3.1 score of 6.7 indicates high severity across confidentiality, integrity and availability. The attack vector is local with low complexity and requires a high-privileged user. The EPSS score of <1% indicates a very low - yet non-zero probability that the vulnerability will be exploited in the wild. Since the vulnerability is not listed in the CISA KEV catalog, current exploitation risk remains moderate, especially for organizations where privileged accounts are present on the same hosts. Internal attackers with sufficient access could exploit this flaw to gain full control.
OpenCVE Enrichment