Oracle Agile Plm Mcad Connector vulnerabilities
20 known vulnerabilities affecting oracle/agile_plm_mcad_connector.
Total CVEs
20
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH3MEDIUM11LOW6
Vulnerabilities
Page 1 of 1
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev3.62021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2026-71067P3HIGHCVSS 8.8v3.62026-08-18
CVE-2026-71067 [HIGH] CWE-306 CVE-2026-71067: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in tak
nvd
CVE-2026-71068P3HIGHCVSS 8.1v3.62026-08-18
CVE-2026-71068 [HIGH] CWE-306 CVE-2026-71068: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in
nvd
CVE-2026-71069P3HIGHCVSS 7.5v3.62026-08-18
CVE-2026-71069 [HIGH] CWE-284 CVE-2026-71069: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in t
nvd
CVE-2026-71070P3MEDIUMCVSS 6.5v3.62026-08-18
CVE-2026-71070 [MEDIUM] CWE-284 CVE-2026-71070: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in u
nvd
CVE-2026-71075P4MEDIUMCVSS 5.9v3.62026-08-18
CVE-2026-71075 [MEDIUM] CWE-284 CVE-2026-71075: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to
nvd
CVE-2026-71076P4MEDIUMCVSS 5.3v3.62026-08-18
CVE-2026-71076 [MEDIUM] CWE-284 CVE-2026-71076: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in
nvd
CVE-2026-71087P4MEDIUMCVSS 5.3v3.62026-08-18
CVE-2026-71087 [MEDIUM] CWE-200 CVE-2026-71087: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks of this vulnerability can result in
nvd
CVE-2026-71077P4MEDIUMCVSS 5.3v3.62026-08-18
CVE-2026-71077 [MEDIUM] CWE-284 CVE-2026-71077: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to
nvd
CVE-2020-17521P4MEDIUMCVSS 5.5v3.4v3.62020-12-07
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this f
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected,
nvd
CVE-2026-71088P4MEDIUMCVSS 4.8v3.62026-08-18
CVE-2026-71088 [MEDIUM] CWE-284 CVE-2026-71088: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a pe
nvd
CVE-2026-71071P4MEDIUMCVSS 4.6v3.62026-08-18
CVE-2026-71071 [MEDIUM] CWE-284 CVE-2026-71071: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to com
nvd
CVE-2026-71066P4MEDIUMCVSS 4.5v3.62026-08-18
CVE-2026-71066 [MEDIUM] CWE-284 CVE-2026-71066: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Su
nvd
CVE-2026-71078P4MEDIUMCVSS 4.2v3.62026-08-18
CVE-2026-71078 [MEDIUM] CWE-284 CVE-2026-71078: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Suc
nvd
CVE-2026-71080P4LOWCVSS 3.7v3.62026-08-18
CVE-2026-71080 [LOW] CWE-284 CVE-2026-71080: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM MCAD Connector executes to com
nvd
CVE-2026-71089P4LOWCVSS 3.3v3.62026-08-18
CVE-2026-71089 [LOW] CWE-284 CVE-2026-71089: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Success
nvd
CVE-2026-71072P4LOWCVSS 3.3v3.62026-08-18
CVE-2026-71072 [LOW] CWE-284 CVE-2026-71072: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successf
nvd
CVE-2026-71082P4LOWCVSS 2.5v3.62026-08-18
CVE-2026-71082 [LOW] CWE-284 CVE-2026-71082: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Succes
nvd
CVE-2026-71081P4LOWCVSS 1.9v3.62026-08-18
CVE-2026-71081 [LOW] CWE-284 CVE-2026-71081: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Succe
nvd
CVE-2026-71083P4LOWCVSS 1.8v3.62026-08-18
CVE-2026-71083 [LOW] CWE-284 CVE-2026-71083: Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Succe
nvd