Executive brief
Oracle Agile Engineering Data Management is used for product lifecycle and engineering data organization within supply chain operations. A vulnerability in the installation component allows a privileged attacker with local system access to fully compromise the system, potentially taking control of all data and operations managed by this application.
Technical details
This is a local privilege escalation vulnerability in the Install component of Oracle Agile Engineering Data Management version 6.2.1. The vulnerability requires high privilege and local system logon access, making it difficult to exploit. Successful exploitation allows an attacker with existing infrastructure access to gain complete control over the Agile Engineering Data Management system, affecting confidentiality, integrity, and availability. The exact root cause and patch status are not fully documented in available sources.
Affected products
- Oracle Agile Engineering Data Management 6.2.1
Timeline
- 2026-08-18: disclosed