Impact
Vulnerability in the Engineering Communication Interface of Oracle Agile Engineering Data Management allows an unauthenticated attacker with network access via HTTP to update, insert, or delete data, and to read a subset of accessible data. The flaw permits bypassing expected data protection controls, resulting in compromised confidentiality and integrity. The CVSS vector indicates moderate impact with confidentiality and integrity reductions, while availability is unaffected.
Affected Systems
Oracle Corporation’s Oracle Agile Engineering Data Management component (Engineering Communication Interface) version 6.2.1, part of the Oracle Supply Chain Management suite.
Risk and Exploitability
The CVSS score of 4.8 suggests moderate risk, and the EPSS score is less than 1%. The vulnerability is not listed in CISA’s KEV catalog, indicating modest evidence of active exploitation. The likely attack vector is a network-based intrusion via HTTP without authentication. Although described as difficult to exploit, the lack of required credentials means that an attacker with network connectivity could potentially manipulate or read restricted data, affecting data integrity and confidentiality.
OpenCVE Enrichment