Impact
The weakness in the CAX Client component of Oracle Agile PLM MCAD Connector 3.6 allows an attacker with local access to read restricted data. The vulnerability is a classic sensitive information exposure that results in confidentiality impact when the attacker logs onto the infrastructure where the Connector is running. Successful exploitation does not affect integrity or availability, but it permits the attacker to survey a subset of data readable through the Connector.
Affected Systems
Oracle Corporation’s Oracle Agile PLM MCAD Connector, version 3.6. No other versions are reported as affected. The product is part of Oracle Supply Chain and the specific component impacted is the CAX Client. Administrators should confirm that any deployment of Connector 3.6 is identified as vulnerable.
Risk and Exploitability
The CVSS vector indicates a local attack with low privilege and no user interaction. The base score of 2.5 reflects a low risk to confidentiality only. Because the EPSS score is <1% and the vulnerability is not in CISA’s KEV catalogue, there is no evidence of active exploitation. The attack requires that the attacker already has logon rights on the host where the Connector runs, making it a local privilege issue rather than a remote surface. With this limited scope, the overall threat is low, but any exposure of sensitive data can still be significant to the organization’s trust and regulatory posture.
OpenCVE Enrichment