Executive brief
A vulnerability exists in the installation component of Oracle Agile Engineering Data Management, a tool used for managing engineering product data and supply chain workflows. A low-privileged user with access to the underlying system could potentially cause a partial service outage, disrupting business operations. Exploiting this issue requires a legitimate user to perform a specific action, such as clicking a link or opening a file provided by the attacker.
Technical details
A vulnerability in the 'Install' component of Oracle Agile Engineering Data Management version 6.2.1 allows for a partial denial of service (DoS). The flaw is easily exploitable by a low-privileged attacker who has local logon access to the infrastructure where the software is running. Successful exploitation requires human interaction from a user other than the attacker (UI:R). The impact is limited to availability, with no reported impact on data confidentiality or integrity. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD record published