Impact
A vulnerability exists in the Oracle Agile PLM MCAD Connector component, specifically the CAX Client. An attacker who has local system logon privileges on the infrastructure where the connector runs can exploit this flaw to compromise the logic of the connector. Successful exploitation results in unauthorized access to critical data, with a confidentiality impact classified as high while integrity and availability remain unaffected.
Affected Systems
The affected product is Oracle Agile PLM MCAD Connector version 3.6, distributed by Oracle Corporation. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity, and the EPSS score of less than 1% suggests that the probability of exploitation is low but non‑zero. The flaw is not currently listed catalog. Exploitation requires an attacker with low privileged logon on the target infrastructure, so the attack vector is local. Once accessed, the attacker can read or download all data that the connector is permitted to access.
OpenCVE Enrichment