Impact
Vulnerability in the Oracle Agile PLM MCAD Connector allows an unauthenticated attacker with network access via HTTP to compromise the component. The flaw can lead to a full takeover of the connector and consequently affects confidentiality, integrity, and availability. The CVSS v3.1 base score of 8.1 reflects the significant impact on these three core assets.
Affected Systems
The affected product is Oracle Agile PLM MCAD Connector version 3.6, part of Oracle Supply Chain. Only this version is identified as vulnerable according to the vendor's advisory.
Risk and Exploitability
The CVSS v3.1 base score is 8.1, indicating high severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the CVSS vector, the likely attack vector is network access via HTTP, with no authentication or user interaction required. Exploitation requires only that the attacker can reach the connector over the network.
OpenCVE Enrichment