Impact
A flaw in the Web Services Security component of Oracle Agile Engineering Data Management 6.2.1 allows a low‑privileged attacker with network access over HTTP to bypass access controls (CWE‑284). The vulnerability can enable the attacker to take over the entire application, compromising confidentiality, integrity, and availability.
Affected Systems
Oracle Agile Engineering Data Management 6.2.1 is the only version documented as affected; no other releases are mentioned.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity, while the EPSS score of <1% suggests a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. An attacker only requires network connectivity to the HTTP endpoint and does not need elevated privileges, making the attack vector readily available over the network.
OpenCVE Enrichment