Impact
A local vulnerability in Oracle Agile PLM MCAD Connector version 3.6 allows an attacker who has logged onto the host infrastructure to gain unauthorized update, insert or delete rights to the connector’s data, read protected data, or initiate a partial denial of service. The flaw requires that the attacker already have local access and that an additional human interaction from another user triggers the effect. The vulnerability is rated moderate, with a CVSS v3.1 base score of 4.5, and impacts confidentiality, integrity and availability for the affected component.
Affected Systems
Oracle Corporation’s Agile PLM MCAD Connector, version 3.6, is impacted. No other product versions or vendors are listed as affected.
Risk and Exploitability
The CVSS score of 4.5 and an EPSS of less than 1% indicate a modest likelihood of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Exploitation requires local host access and a non‑attacker’s human interaction, limiting the attack surface. Nonetheless, the potential for data integrity and availability loss warrants prompt attention and monitoring.
OpenCVE Enrichment