Executive brief
Oracle Agile Engineering Data Management is a product used to manage engineering data and communications in supply chain operations. A vulnerability in the Engineering Communication Interface component allows low-privileged network attackers to gain unauthorized access to, create, modify, or delete sensitive engineering data, potentially affecting confidentiality and integrity of critical supply chain information.
Technical details
This is an authorization bypass or access control vulnerability in the Engineering Communication Interface component of Oracle Agile Engineering Data Management version 6.2.1. The vulnerability is difficult to exploit but requires only low privilege access and network connectivity via HTTP; no user interaction is needed. A successful attack allows an attacker to read, create, modify, or delete critical data within the application, and may impact additional connected Oracle products due to a scope change. The vulnerability is classified as high severity with a CVSS 3.1 score of 8.2 (high confidentiality and integrity impacts).
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-08-18: disclosed