Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287)

Share:

Oracle has released a security patch for CVE-2024-21287, a remotely exploitable vulnerability in the Oracle Agile PLM Framework that is, according to Tenable researchers, being actively exploited by attackers.

About CVE-2024-21287

Oracle Agile PLM Framework is an enterprise product lifecycle management solution that enables collaboration between the various teams involved.

CVE-2024-21287 affects version 9.3.6 of the Agile PLM Framework – more specifically, the Agile Software Development Kit and the Process Extension components.

“This vulnerability is remotely exploitable [via HTTP and HTTPS protocol] without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in file disclosure,” Oracle shared in the associated advisory.

The NVD entry for the vulnerability details that “successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data”.

CrowdStrike’s researchers Joel Snape and Lutz Wolf have been credited with reporting the flaw.

Exploitation

Tenable Research’s threat landscape status says that “in the wild exploitation has been observed”.

“Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible,” the company said, but did not mention the vulnerability being leveraged by attackers.

We’ve asked for more details from Oracle, Tenable and Crowdstrike and we’ll update this article if we receive a relevant reply.

UPDATE (November 19, 2024, 11:55 a.m. ET):

In a separate post, Eric Maurice, VP of Security Assurance at Oracle, said the vulnerability “was reported as being actively exploited ‘in the wild’ by CrowdStrike”.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:43 pm, Jul 1, 2025
weather icon 24°C
L: 23° | H: 26°
scattered clouds
Humidity: 65 %
Pressure: 1014 mb
Wind: 10 mph NNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 41%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:47 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
23° | 26°°C 0.38 mm 38% 11 mph 80 % 1022 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
14° | 19°°C 1 mm 100% 13 mph 81 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 23°°C 0 mm 0% 5 mph 67 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 20°°C 0 mm 0% 6 mph 74 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
18° | 18°°C 0.2 mm 20% 5 mph 80 % 1017 mb 0 mm/h
Tomorrow 10:00 am
weather icon
21° | 21°°C 0.2 mm 20% 6 mph 71 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
19° | 19°°C 0.38 mm 38% 4 mph 69 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
23° | 23°°C 0.35 mm 35% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
23° | 23°°C 0.01 mm 1% 11 mph 28 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 10 mph 34 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,661.91
-1.37%
Ethereum(ETH)
€2,039.29
-3.50%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.85
-4.33%
Solana(SOL)
€124.08
-6.30%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134301
-4.70%
Shiba Inu(SHIB)
€0.000009
-2.58%
Pepe(PEPE)
€0.000008
-5.83%
Scroll to Top