Impact
The Oracle Agile PLM MCAD Connector contains a flaw that permits a low‑privileged attacker reachable over HTTP to compromise the connector and obtain confidential data. The description states that unauthorized or complete access to all connector data is possible; it does not explicitly mention an authentication bypass, but the sentence that a low‑privileged attacker can compromise the product implies that authentication or authorization controls are subverted. Thus, the analysis infers that the vulnerability involves an access‑control weakness that permits data exfiltration without proper privileges.
Affected Systems
Oracle Agile PLM MCAD Connector, version 3.6, supplied by Oracle Corporation, is the sole affected version according to the current information.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 reflects a moderate severity, with only confidentiality impacted. The EPSS score of less than 1% suggests a low probability of exploitation so far, and the vulnerability is not listed in CISA’s KEV catalog. Still, the attack vector is network‑based via HTTP, requires only low privileges, and thus offers an approachable path for a potential attacker. Consequently, administrators should regard it as a medium‑to‑high risk to confidentiality, especially if the connector is exposed to untrusted networks.
OpenCVE Enrichment