Executive brief
Oracle Agile Engineering Data Management is a supply-chain planning tool that manages engineering project data. An unauthenticated network attacker can exploit a flaw in the Engineering Communication Interface component to read, modify, and delete sensitive project data, compromising data integrity and exposing confidential engineering information.
Technical details
This is a logic or authorization bypass vulnerability in the Engineering Communication Interface component of Oracle Agile Engineering Data Management 6.2.1. The flaw allows unauthenticated attackers with network access via HTTP to bypass access controls and manipulate data. Attack preconditions are minimal—no authentication or user interaction is required, though exploitation is rated as difficult (high attack complexity). A successful exploit grants unauthorized read, create, update, and delete access to a subset of the product's data assets, affecting both confidentiality and integrity. A patch or update is likely available through Oracle's regular security update channels.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-08-18: disclosed