Impact
A flaw in the Web Services Security component of Oracle Agile Engineering Data Management allows an unauthenticated attacker to access the system via HTTP and take complete control, exposing confidential data, corrupting integrity, and disrupting availability. The weakness is identified as CWE-284, Improper Access Control, and enables a remote attacker to abuse the application without credentials.
Affected Systems
Oracle Agile Engineering Data Management version 6.2.1 is affected by this vulnerability.
Risk and Exploitability
The CVSS base score of 8.1 indicates severity, and the attack vector is inferred to be remote over HTTP with no authentication required. The EPSS score of < 1% signals a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the potential for full system takeover warrants close attention if the flaw becomes publicly known.
OpenCVE Enrichment