Executive brief
Oracle Agile Engineering Data Management is a product suite used by enterprises to manage engineering data and supply chain processes. A vulnerability in the Engineering Communication Interface component allows a low-privileged local user with system access to gain complete control over the application, compromising confidentiality, integrity, and availability of sensitive engineering and supply chain data.
Technical details
This is a local privilege escalation vulnerability in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. The vulnerability is difficult to exploit and requires an authenticated attacker with low-privilege local access to the infrastructure running the product. Successful exploitation results in complete compromise of the affected application with full confidentiality, integrity, and availability impact. The CVSS 3.1 score of 7.0 reflects the high impact of successful exploitation, though the requirement for local access and elevated exploitation difficulty limit the attack surface.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-08-18: disclosed