Impact
The vulnerability, classified as an authority inconsistency (CWE-284), has a CVSS base score of 6.4. It allows a high‑privileged local attacker who has logon access to the underlying infrastructure to compromise the Oracle Agile Engineering Data Management application. Successful exploitation can lead to a full takeover, resulting in loss of confidentiality, integrity, and availability for the application.
Affected Systems
Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain’s data management suite, is the only supported version identified as affected.
Risk and Exploitability
The risk is moderate because the attack vector is local and the EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment