Impact
A flaw in Oracle Agile PLM MCAD Connector, version 3.6, allows a low-privileged attacker to use an HTTP request to compromise the entire application. The weakness, identified as CWE‑306 (Improper Handling of Authentication), can lead to full system takeover, causing loss of confidentiality, integrity and availability.
Affected Systems
Oracle Agile PLM MCAD Connector version 3.6, part of Oracle Supply Chain solutions, specifically the CAX Client component. No other products or versions are listed as affected by this CVE.
Risk and Exploitability
The CVSS 3.1 base score of 8.8 indicates severe impact across confidentiality, integrity and availability. The EPSS score of <1% shows a low but non‑zero probability of exploitation, meaning the vulnerability has not yet been widely used but remains a realistic threat. Because the flaw can be triggered purely through a network‑based HTTP request from a low‑privileged attacker, the likely attack vector is a simple HTTP request to an exposed endpoint of the MCAD Connector, and the attacker requires only network connectivity and low‑privilege access. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment