Impact
A flaw in the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6 permits an attacker with low‑privileged credentials on the host to compromise the connector. The vulnerability, identified as a CWE-284 Access Control weakness, can be exercised to interrupt or degrade the connector’s availability, resulting in a partial denial of service. The weakness solely affects availability and does not expose confidential or integrity data.
Affected Systems
Oracle Agile PLM MCAD Connector, version 3.6, distributed by Oracle Corporation.
Risk and Exploitability
The CVSS base score of 3.3 reflects a low severity impact focused on availability, while an EPSS score of less than 1% indicates a very low but nonzero likely exploitation chance. The vulnerability is not listed in the CISA KEV catalog, showing no current widespread exploitation. Attackers would need local access with limited privileges on the system where the connector runs, which is inferred from the description.
OpenCVE Enrichment