Impact
This vulnerability resides in the Oracle Agile PLM MCAD Connector component known as CAX Client. A low‑privileged attacker with network access can send HTTP requests that trigger the flaw, allowing the attacker to compromise the component. A successful exploit results in full takeover, affecting confidentiality, integrity, and availability.
Affected Systems
Affected systems are Oracle Agile PLM MCAD Connector version 3.6. The product is delivered by Oracle Corporation as part of its Supply Chain offerings.
Risk and Exploitability
The CVSS v3.1 base score is 7.5, indicating high severity and direct impact on all three pillars. The EPSS score is < 1%, suggesting a low probability of exploitation, but the lack of KEV listing does not diminish the risk. Attackers likely exploit the flaw over the network via HTTP from a low‑privileged state, making remediation essential.
OpenCVE Enrichment