Executive brief
A vulnerability exists in Oracle Agile Engineering Data Management, a system used for managing engineering product data and supply chain processes. An attacker with basic user access can remotely crash the system or cause it to become unresponsive. This could lead to significant operational delays and a total loss of availability for the engineering data management service.
Technical details
A vulnerability in the Core component of Oracle Agile Engineering Data Management (version 6.2.1) allows for a denial-of-service (DoS) attack. The flaw is easily exploitable by a low-privileged attacker with network access via TCP. Successful exploitation allows the attacker to cause a frequently repeatable crash or a system hang, resulting in a complete loss of availability. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory