Impact
Based on the description, it is inferred that the flaw originates from missing proper authorization checks in the Engineering Communication Interface component of Oracle Agile Engineering Data Management. An attacker who can reach the system over HTTP and has low privileges can exploit this weakness to create, delete, or modify any data stored by the system, thereby compromising confidentiality and integrity of critical business information. The vulnerability also has a scope change and may impact additional products beyond Oracle Agile Engineering Data Management.
Affected Systems
Oracle Corporation's Oracle Agile Engineering Data Management version 6.2.1 is affected.
Risk and Exploitability
The CVSS 3.1 base score of 8.2 highlights a high‑severity vulnerability with serious confidentiality and integrity impacts. Because the vulnerability is exploitable over the network with only HTTP access and low privileges, the barrier to attack is low; the likely attack vector is a network compromise or simple web‑based exploitation. The EPSS score is < 1% and the flaw is not listed in the CISA KEV catalog, but the high CVSS score and lack of mitigations suggest a significant risk to affected deployments. This scope change means that attacks could also compromise other components of Oracle's Supply Chain suite.
OpenCVE Enrichment