Impact
The Oracle Agile PLM MCAD Connector product (CAX Client component) has a weakness that allows an attacker who already has high‑privilege access to the infrastructure where the connector runs to perform unauthorized updates, inserts or deletes on data that the connector exposes. The vulnerability is an improper access control flaw, which can lead to a compromise of the integrity of records managed by the connector. No confidentiality or availability impacts are reported.
Affected Systems
Affected vendors include Oracle Corporation. The product is Oracle Agile PLM MCAD Connector, version 3.6. No other versions are mentioned in the official advisories.
Risk and Exploitability
The CVSS 3.1 base score is 1.9, indicating a low severity integrity impact. The exploit requires a local attacker with high‑privilege user credentials on the host machine; the vector is inferred to be local network access or direct system login, as the description states an attacker with logon to the infrastructure can exploit it. The EPSS score indicates a probability of exploitation less than 1%, and the vulnerability has not been added to CISA’s KEV catalog. Because the attack requires existing privileged access, the overall risk to isolated or well‑segmented environments is limited, but it remains an integrity risk for any environment where users have elevated local rights or where the connector is deployed on a compromised host.
OpenCVE Enrichment