Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287)

Share:

Oracle has released a security patch for CVE-2024-21287, a remotely exploitable vulnerability in the Oracle Agile PLM Framework that is, according to Tenable researchers, being actively exploited by attackers.

About CVE-2024-21287

Oracle Agile PLM Framework is an enterprise product lifecycle management solution that enables collaboration between the various teams involved.

CVE-2024-21287 affects version 9.3.6 of the Agile PLM Framework – more specifically, the Agile Software Development Kit and the Process Extension components.

“This vulnerability is remotely exploitable [via HTTP and HTTPS protocol] without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in file disclosure,” Oracle shared in the associated advisory.

The NVD entry for the vulnerability details that “successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data”.

CrowdStrike’s researchers Joel Snape and Lutz Wolf have been credited with reporting the flaw.

Exploitation

Tenable Research’s threat landscape status says that “in the wild exploitation has been observed”.

“Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible,” the company said, but did not mention the vulnerability being leveraged by attackers.

We’ve asked for more details from Oracle, Tenable and Crowdstrike and we’ll update this article if we receive a relevant reply.

UPDATE (November 19, 2024, 11:55 a.m. ET):

In a separate post, Eric Maurice, VP of Security Assurance at Oracle, said the vulnerability “was reported as being actively exploited ‘in the wild’ by CrowdStrike”.

Zeljka Zorz

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:29 pm, Feb 3, 2025
weather icon 8°C
L: 7° | H: 9°
overcast clouds
Humidity: 81 %
Pressure: 1024 mb
Wind: 9 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
7° | 9°°C 0 mm 0% 8 mph 97 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
5° | 9°°C 0.2 mm 20% 14 mph 98 % 1027 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 89 % 1044 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
3° | 8°°C 0 mm 0% 10 mph 86 % 1045 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
3° | 6°°C 0 mm 0% 14 mph 91 % 1039 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 8°°C 0 mm 0% 8 mph 86 % 1025 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 7°°C 0 mm 0% 5 mph 91 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 97 % 1024 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 5 mph 98 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
7° | 7°°C 0 mm 0% 7 mph 91 % 1023 mb 0 mm/h
Tomorrow 6:00 am
weather icon
6° | 6°°C 0 mm 0% 9 mph 95 % 1022 mb 0 mm/h
Tomorrow 9:00 am
weather icon
7° | 7°°C 0 mm 0% 11 mph 90 % 1023 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 13 mph 79 % 1022 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,756.24
-3.76%
Ethereum(ETH)
€2,518.10
-16.10%
Tether(USDT)
€0.98
0.15%
XRP(XRP)
€2.32
-14.72%
Solana(SOL)
€190.98
-7.19%
USDC(USDC)
€0.98
0.00%
Dogecoin(DOGE)
€0.246701
-14.10%
Shiba Inu(SHIB)
€0.000015
-14.85%
Pepe(PEPE)
€0.000010
-21.08%
Scroll to Top