CVE-2026-61187: Low severity Oracle Oracle Agile Engineering Data Management vulnerability
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile Engineering Data Management. CVSS 3.1 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Agile Engineering Data Management (Install)to a version that resolves this vulnerability.Fixed in 6.2.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61187?
The severity of CVE-2026-61187 is low with a score of 2.8.
How do I fix CVE-2026-61187?
To address CVE-2026-61187, upgrade to a non-vulnerable version of Oracle Agile Engineering Data Management.
What systems are affected by CVE-2026-61187?
CVE-2026-61187 affects version 6.2.1 of Oracle Agile Engineering Data Management.
What type of access is required to exploit CVE-2026-61187?
A low privileged attacker with logon access to the infrastructure can exploit CVE-2026-61187.
What is the risk level associated with CVE-2026-61187?
CVE-2026-61187 has a risk level classified as 15.