Impact
This vulnerability resides in the CAX Client component of Oracle Agile PLM MCAD Connector. A low‑privileged attacker who can log onto the host where the connector runs can use the flaw to create, delete, or alter critical data, and to read restricted data. The defect does not grant arbitrary code execution but enables tampering and data exposure within the PLM system.
Affected Systems
Oracle Agile PLM MCAD Connector 3.6 is the only version identified as vulnerable. The description indicates that a successful exploit may also affect other components of the Oracle Agile PLM environment because the vulnerability has a scope change.
Risk and Exploitability
The CVSS v3.1 base score is 7.3 (high). EPSS is reported as less than 1% and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires local logon, the attacker must already have some access to the system, but the low complexity and low privilege requirements make it relatively easy for an insider or a compromised user to exploit. Once exploited the attacker gains persistent control over critical data and can cause data integrity breaches.
OpenCVE Enrichment