Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287)

Teilen:

Oracle has released a security patch for CVE-2024-21287, a remotely exploitable vulnerability in the Oracle Agile PLM Framework that is, according to Tenable researchers, being actively exploited by attackers.

About CVE-2024-21287

Oracle Agile PLM Framework is an enterprise product lifecycle management solution that enables collaboration between the various teams involved.

CVE-2024-21287 affects version 9.3.6 of the Agile PLM Framework – more specifically, the Agile Software Development Kit and the Process Extension components.

“This vulnerability is remotely exploitable [via HTTP and HTTPS protocol] without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in file disclosure,” Oracle shared in the associated advisory.

The NVD entry for the vulnerability details that “successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data”.

CrowdStrike’s researchers Joel Snape and Lutz Wolf have been credited with reporting the flaw.

Ausbeutung

Tenable Research’s threat landscape status says that “in the wild exploitation has been observed”.

“Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible,” the company said, but did not mention the vulnerability being leveraged by attackers.

We’ve asked for more details from Oracle, Tenable and Crowdstrike and we’ll update this article if we receive a relevant reply.

UPDATE (November 19, 2024, 11:55 a.m. ET):

In a separate post, Eric Maurice, VP of Security Assurance at Oracle, said the vulnerability “was reported as being actively exploited ‘in the wild’ by CrowdStrike”.

Zeljka Zorz

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:37 pm, Juli 1, 2025
Wetter-Symbol 29°C
L: 28° | H: 31°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 53 %
Druck: 1014 mb
Wind: 8 mph NE
Windböe: 10 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 25%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
28° | 31°°C 0 mm 0% 8 mph 54 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 26°°C 0.38 mm 38% 11 mph 80 % 1022 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
24° | 29°°C 0 mm 0% 8 mph 54 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 26°°C 0 mm 0% 5 mph 59 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 22°°C 0 mm 0% 6 mph 70 % 1015 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0.2 mm 20% 5 mph 80 % 1017 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
21° | 21°°C 0.2 mm 20% 6 mph 71 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0.38 mm 38% 4 mph 69 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0.35 mm 35% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
23° | 23°°C 0.01 mm 1% 11 mph 28 % 1020 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,499.39
-1.67%
Ethereum(ETH)
€2,048.94
-3.59%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.84
-5.33%
Solana(SOL)
€123.97
-6.68%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.134200
-4.84%
Shiba Inu(SHIB)
€0.000009
-3.23%
Pepe(PEPE)
€0.000008
-6.77%
Nach oben scrollen