Impact
Oracle Agile PLM MCAD Connector 3.6 contains an access‐control flaw that permits any user who can log on to the infrastructure hosting the connector to read a limited set of data stored within the application. The vulnerability is triggered without authentication from the application’s perspective, but relies on the local presence of a privileged user on the host machine and requires human interaction from an actor other than the attacker. This results in unauthorized disclosure of confidential data that may be sensitive to the organization and its partners.
Affected Systems
The issue affects Oracle Corporation’s Oracle Agile PLM MCAD Connector version 3.6. This version is distributed under the Oracle Agile PLM MCAD Connector product line.
Risk and Exploitability
The CVSS V3.1 base score of 3.3 reflects a low‑severity confidentiality impact. The attack vector is local (AV:L) and requires the attacker to have physical or network access to the system where the connector runs; the required user interaction (UI:R) means the exploit cannot be carried out remotely head‑less. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog. Overall, the likelihood of exploitation is relatively low, but any successful read can compromise confidential information that may be of strategic value to an adversary.
OpenCVE Enrichment