Executive brief
Oracle Agile Engineering Data Management, a tool used to manage product design and engineering data throughout the supply chain, is vulnerable to a denial-of-service attack. An attacker with basic network access and low-level user credentials can cause the system to hang or crash repeatedly. This could disrupt engineering operations and prevent staff from accessing critical design data.
Technical details
A vulnerability in the Core component of Oracle Agile Engineering Data Management version 6.2.1 allows for a denial-of-service (DoS) attack. The flaw is easily exploitable by a low-privileged attacker with network access via TCP. Successful exploitation allows the attacker to cause a hang or a frequently repeatable crash of the application, impacting system availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD