Impact
This vulnerability resides in the Engineering Communication Interface component of the Oracle Agile Engineering Data Management product. A low privileged user who can log on to the infrastructure where the product runs can exploit the issue, gaining unauthorized access to sensitive data and, with the scope change, to additional Oracle products. The flaw permits reading critical data and performing unauthorized updates, inserts, or deletes. The weakness results in a confidentiality impact rated as High and an integrity impact rated as Low.
Affected Systems
Oracle Corporation's Agile Engineering Data Management version 6.2.1 is the only affected release. The vulnerability is confined to that component within the application.
Risk and Exploitability
The CVSS 3.1 base score of 7.3 reflects a local attack with low required privileges and no user interaction, yielding a high confidentiality loss. The EPSS score is reported as less than 1 %, indicating a very low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw has a scope change, a successful local attack could let the attacker access not only the vulnerable application but also other Oracle supply‑chain products tied to the same infrastructure. The ease of exploitation means that an attacker who has insecure local access to the host could immediately leverage the flaw without further networking activity.
OpenCVE Enrichment