Impact
This vulnerability allows a low‑privileged user who can log onto the same infrastructure where Oracle Agile Engineering Data Management runs to exploit an insecure access control flaw. By doing so, the attacker can create, delete, or modify any critical data stored by the product and may gain full read access to all data managed by the system. The flaw directly compromises confidentiality and integrity but does not affect availability.
Affected Systems
Oracle Agile Engineering Data Management version 6.2.1 is affected. The flaw may also impact other Oracle Supply Chain products that share the same Engineering Communication Interface component.
Risk and Exploitability
The base CVSS score is 8.4, indicating a high‑severity vulnerability. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the attack requires only local logon privileges, a compromised host can potentially leverage the flaw to undermine critical data security. The vulnerability is exploitable without network boundary traversal, making it attractive to an internal threat actor or a compromised user.
OpenCVE Enrichment