Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287)

Teilen:

Oracle has released a security patch for CVE-2024-21287, a remotely exploitable vulnerability in the Oracle Agile PLM Framework that is, according to Tenable researchers, being actively exploited by attackers.

About CVE-2024-21287

Oracle Agile PLM Framework is an enterprise product lifecycle management solution that enables collaboration between the various teams involved.

CVE-2024-21287 affects version 9.3.6 of the Agile PLM Framework – more specifically, the Agile Software Development Kit and the Process Extension components.

“This vulnerability is remotely exploitable [via HTTP and HTTPS protocol] without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in file disclosure,” Oracle shared in the associated advisory.

The NVD entry for the vulnerability details that “successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data”.

CrowdStrike’s researchers Joel Snape and Lutz Wolf have been credited with reporting the flaw.

Ausbeutung

Tenable Research’s threat landscape status says that “in the wild exploitation has been observed”.

“Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible,” the company said, but did not mention the vulnerability being leveraged by attackers.

We’ve asked for more details from Oracle, Tenable and Crowdstrike and we’ll update this article if we receive a relevant reply.

UPDATE (November 19, 2024, 11:55 a.m. ET):

In a separate post, Eric Maurice, VP of Security Assurance at Oracle, said the vulnerability “was reported as being actively exploited ‘in the wild’ by CrowdStrike”.

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
3:00 am, Juli 2, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 75 %
Druck: 1015 mb
Wind: 6 mph ENE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 34%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0.26 mm 26% 11 mph 77 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 12 mph 54 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 61 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
16° | 21°°C 1 mm 100% 13 mph 95 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 17°°C 1 mm 100% 12 mph 91 % 1009 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 5 mph 75 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 20°°C 0 mm 0% 8 mph 77 % 1015 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 73 % 1016 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0.2 mm 20% 7 mph 71 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0.26 mm 26% 8 mph 45 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 11 mph 32 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 11 mph 35 % 1023 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
15° | 15°°C 0 mm 0% 7 mph 39 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,542.29
-1.45%
Ethereum(ETH)
€2,040.76
-3.26%
Fesseln(USDT)
€0.85
-0.02%
XRP(XRP)
€1.85
-2.47%
Solana(SOL)
€125.14
-4.43%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134315
-4.09%
Shiba Inu(SHIB)
€0.000009
-1.71%
Pepe(PEPE)
€0.000008
-4.43%
Nach oben scrollen