Impact
The Oracle Agile PLM MCAD Connector version 3.6 contains an access control flaw that permits a low‑privileged attacker with network access via HTTP to read any data exposed by the connector. The vulnerability requires user interaction from a target user not involved in the attack; if exploited the attacker can view confidential information, but does not affect integrity or availability.
Affected Systems
Oracle Agile PLM MCAD Connector 3.6, specifically the CAX Client component, is affected. No other Oracle or third‑party products are listed as vulnerable according to the CNA data.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate confidentiality risk. The EPSS score of less than 1 % shows a very low probability of widespread exploitation, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known active exploits. Successful exploitation requires an attacker with HTTP access and a collaborator user who performs some action. Because user interaction is mandatory and the attack vector is confined to web traffic, the likelihood of automated attacks is low, but sensitive data could still be exposed if the attacker can recruit an internal user.
OpenCVE Enrichment