Impact
Oracle Agile PLM MCAD Connector version 3.6 includes a vulnerability in the CAX Client component that permits a high‑privilege attacker who has logged into the host system to read a subset of data exposed by the connector. The exploitation is considered difficult and requires interaction with a legitimate, non‑attacker user. The impact is an unauthorized disclosure of sensitive information, as reflected in the CVSS score of 1.8 with a low confidentiality impact.
Affected Systems
The vulnerability affects Oracle Agile PLM MCAD Connector version 3.6 (Oracle Supply Chain). It applies to installations of the CAX Client component that run on an infrastructure where Oracle Agile PLM MCAD Connector is deployed.
Risk and Exploitability
The CVSS score of 1.8 indicates low severity, with confidentiality impact limited to low. The EPSS score is <1%, showing a negligible probability of exploitation. Exploitation requires a high‑privileged user on the host machine and human interaction, making the attack difficult to execute. No evidence of active exploitation has been reported, and the issue is not listed in the CISA KEV catalog. Consequently, the immediate threat is low, but environments that rely on this connector should ensure that only trusted users have privileged access and monitor logs for any unauthorized read attempts.
OpenCVE Enrichment