Description
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Web Services Security component of Oracle Agile Engineering Data Management 6.2.1 allows a low‑privileged attacker with network access over HTTP to bypass access controls (CWE‑284). The vulnerability can enable the attacker to take over the entire application, compromising confidentiality, integrity, and availability.

Affected Systems

Oracle Agile Engineering Data Management 6.2.1 is the only version documented as affected; no other releases are mentioned.

Risk and Exploitability

The CVSS v3.1 base score of 8.8 indicates high severity, while the EPSS score of <1% suggests a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker only requires network connectivity to the HTTP endpoint and does not need elevated privileges, making the attack vector readily available over the network.

Generated by OpenCVE AI on August 20, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle-issued patch or update that addresses the Web Services Security flaw in Agile Engineering Data Management 6.2.1.
  • Restrict HTTP access to the application by implementing firewall rules or IP whitelisting so that only trusted networks can reach the vulnerable endpoint.
  • If the Web Services Security functionality is not required, disable or uninstall the component to eliminate the attack surface.

Generated by OpenCVE AI on August 20, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*

Thu, 20 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Web Services Security Access Control Flaw in Oracle Agile Engineering Data Management

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title HTTP-based Low-Privilege Web Services Security Vulnerability Enabling Full Compromise of Oracle Agile Engineering Data Management
Weaknesses CWE-287

Wed, 19 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title HTTP-based Low-Privilege Web Services Security Vulnerability Enabling Full Compromise of Oracle Agile Engineering Data Management
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Engineering Data Management. Successful attacks of this vulnerability can result in takeover of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle agile Engineering Data Management
CPEs cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle agile Engineering Data Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Agile Engineering Data Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:04:49.051Z

Reserved: 2026-08-04T22:06:34.614Z

Link: CVE-2026-71052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:05.063

Modified: 2026-08-24T15:52:03.720

Link: CVE-2026-71052

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:30:05Z

Weaknesses