Impact
An unauthenticated attacker who can reach the Oracle Agile PLM MCAD Connector over HTTP can read a restricted subset of the data exposed by the service. The vulnerability does not alter the data or cause availability problems, but it allows confidential information to be retrieved without permission, potentially exposing sensitive product information. The weakness involved is improper access control and information exposure, corresponding to CWE-200.
Affected Systems
The product impacted is Oracle Agile PLM MCAD Connector, version 3.6, part of Oracle Supply Chain’s CAX Client component, as managed by Oracle Corporation. Only the HTTP interface of this connector is exposed to the network for legitimate use, and that interface is the vector for the noted data read attack.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate security impact range, focusing on confidentiality. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is network‑based over HTTP and requires no authentication or privileges; thus an attacker with network reach can simply issue normal HTTP requests to obtain the data.
OpenCVE Enrichment