Executive brief
Oracle Agile Engineering Data Management is a data management system used in supply chain operations. An attacker with high-level access to the infrastructure hosting this application can exploit a local vulnerability to gain complete control of the system, affecting data confidentiality, integrity, and availability.
Technical details
This is a local privilege escalation vulnerability in Oracle Agile Engineering Data Management version 6.2.1, specifically in the Install component. The vulnerability is easily exploitable by a high-privileged local attacker with logon access to the infrastructure where the application executes. Successful exploitation results in complete takeover of the application with impacts to confidentiality, integrity, and availability. The vulnerability requires local system access and high privileges but no user interaction. A patch or mitigation has not been specified in the available advisory information.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-08-18: disclosed