Impact
The vulnerability resides in the CAX Client component of Oracle Agile PLM MCAD Connector version 3.6 and is an improper access control flaw. A low‑privileged attacker with logon to the host where the connector runs can read any data the connector stores, potentially exposing critical confidential information while leaving integrity and availability intact. The CVSS 3.1 score of 5.5 underscores a medium severity impact focused on confidentiality.
Affected Systems
Oracle Agile PLM MCAD Connector version 3.6, part of Oracle Supply Chain, is affected. Users running this connector on any infrastructure where the CAX Client component executes and where local logon privileges are granted can be impacted. All installations of this product that have not been patched or upgraded remain vulnerable.
Risk and Exploitability
The CVSS base score of 5.5 indicates a medium risk level. The EPSS score of less than 1 % implies that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a local, low‑privileged logged‑on session on the system hosting the connector, making the threat surface limited to environments with insufficiently restricted local accounts. If an attacker gains that access, they can read confidential data but cannot modify data or disrupt service.
OpenCVE Enrichment