Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, classified as an authority inconsistency (CWE-284), has a CVSS base score of 6.4. It allows a high‑privileged local attacker who has logon access to the underlying infrastructure to compromise the Oracle Agile Engineering Data Management application. Successful exploitation can lead to a full takeover, resulting in loss of confidentiality, integrity, and availability for the application.

Affected Systems

Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain’s data management suite, is the only supported version identified as affected.

Risk and Exploitability

The risk is moderate because the attack vector is local and the EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 26, 2026 at 04:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update to Oracle Agile Engineering Data Management 6.2.1 or later, if available.
  • Restrict privileged access on the infrastructure hosting the application and enforce least‑privilege principles to limit the pool of potential attackers.
  • Monitor system logs and configuration changes for anomalous behavior, and conduct regular security audits to verify that the application and its underlying infrastructure remain uncompromised.

Generated by OpenCVE AI on August 26, 2026 at 04:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*

Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enables Full Takeover of Oracle Agile Engineering Data Management

Tue, 25 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enables Full Takeover of Oracle Agile Engineering Data Management
Weaknesses CWE-269
CWE-710

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-710

Fri, 21 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allows Oracle Agile Data Management Takeover
Weaknesses CWE-284

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allows Oracle Agile Data Management Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:12:41.929Z

Reserved: 2026-08-04T22:06:34.591Z

Link: CVE-2026-70712

cve-icon Vulnrichment

Updated: 2026-08-25T15:06:08.214Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:23.493

Modified: 2026-09-04T13:19:35.637

Link: CVE-2026-70712

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T04:30:16Z

Weaknesses