Impact
The Oracle Agile PLM MCAD Connector 3.6 has been identified to allow a low‑privilege user with local logon to perform unauthorized updates, inserts, or deletions of data, read restricted data, and induce a partial denial of service. The vulnerability requires the attacker to be able to log onto the infrastructure where the connector is running and involves a human interaction step from another person; based on the description, it is inferred that exploitation is moderately difficult. The CVSS v3.1 base score is 4.2, reflecting low to moderate impacts to confidentiality, integrity, and availability.
Affected Systems
Affected systems are Oracle Corporation’s Agile PLM MCAD Connector component known as the CAX Client, specifically version 3.6. The connector is part of Oracle Supply Chain Solutions and is typically deployed on corporate infrastructure that hosts supply‑chain management data.
Risk and Exploitability
Given the CVSS score of 4.2 and the EPSS score of less than 1%, the overall risk is considered low to moderate. Based on the description, it is inferred that the likelihood of large‑scale or automated exploitation is limited. The vulnerability is not listed in the CISA KEV catalog, and exploitation requires physical or remote local access to the infrastructure plus a second user’s cooperation. Nonetheless, the possibility of data tampering and disruption of the connector’s services warrants review and timely patching.
OpenCVE Enrichment