Impact
The vulnerability resides in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. It allows an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the product runs to compromise the system. Successful exploitation can expose critical data (high confidentiality impact) and permit unauthorized read, insert, update, or delete operations on accessible data (low integrity impact). The weakness involves improper access control that lets attackers bypass authentication checks and perform data operations that are not permitted for unauthenticated users.
Affected Systems
Oracle Agile Engineering Data Management version 6.2.1, part of Oracle Supply Chain Management, specifically the Engineering Communication Interface component.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a moderate to high severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and it is not catalogued in CISA's KEV. However, because the attack requires physical or network segment access to the hardware's communication interface, the threat is limited to environments where an attacker can reach that segment. The serious confidentiality impact warrants treating it as a higher risk for deployments exposed to physical or segment‑level access.
OpenCVE Enrichment