Agile Engineering Data Management

Vendor:

First CVE: Jan 21, 2016 · Active for 10 years

38
Total CVEs
More Total CVEs than 98% of tracked products
4.8
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 30% of tracked products
5.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Agile Engineering Data Management over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2016
10 years ago
Most Recent CVE
Jul 21, 2026
7 days ago

CVE Severity & Scoring

Agile Engineering Data Management38 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local8 (21.1%)
Network26 (68.4%)
Unknown2 (5.3%)
Physical0 (0.0%)
Adjacent Network2 (5.3%)
Attack Complexity
Low21 (55.3%)
High15 (39.5%)
Unknown2 (5.3%)
User Interaction
None27 (71.1%)
Unknown2 (5.3%)
Required9 (23.7%)
Privileges Required
Low11 (28.9%)
High1 (2.6%)
None24 (63.2%)
Unknown2 (5.3%)

Top CVEs

Signals from CVEs in this product scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for e
Feb 24, 20209.899YESYES
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener
Apr 6, 20179.897YESYES
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.584NOYES
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payl
Jul 14, 20207.577NOYES
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL po
May 4, 20177.567NOYES
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a f
May 20, 20207.066NOYES
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a su
Jul 14, 20207.560NONO
Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploit
Jul 21, 20269.437NONO
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect conf
Jul 21, 20169.832NONO

Exploit Exposure

Signals from CVEs in this product scope (38 CVEs).

CISA KEV
2 CVEs
5.3% of CVEs· 98th percentile
Metasploit
1 CVE
2.6% of CVEs· 97th percentile
Nuclei
4 CVEs
10.5% of CVEs· 97th percentile
ExploitDB
3 CVEs
7.9% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (38 CVEs).

Media Mentions

Signals from CVEs in this product scope (38 CVEs).

Top CNAs Publishing CVEs For Agile Engineering Data Management

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.2.2.014.80.9%00
6.2.1.0316.522.3%25
6.2.0.055.42.0%00
6.2.028.772.8%12
6.1.3.065.31.8%00
6.1.328.772.8%12
6.1.2.222.91.0%00