Oracle News Articles

Recent news articles refferecing the vendors vulnerabilities.

CVE-2024-21182: Oracle WebLogic Server Flaw Exploit Code Released

CVE-2024-21182 is a high-severity vulnerability identified in Oracle WebLogic Server. This security flaw affects specific versions of the software, namely Oracle WebLogic Server 12.2.1.4.0 and 14.1.1.0.0. The vulnerability allows remote attackers to exploit the system without requiring authenticatio...

3 weeks ago

Oracle WebLogic Server Vulnerability Lets Attackers Compromise the Server Remotely

A vulnerability, tracked as CVE-2024-21182, in Oracle WebLogic Server, affecting versions 12.2.1.4.0 and 14.1.1.0.0. The flaw, rated with a CVSS score of 7.5 (High), allows unauthenticated attackers to compromise servers remotely via the T3 and IIOP protocols.

3 weeks ago

PoC Exploited Released for Oracle Weblogic Server Vulnerability

Security researchers have warned that a Proof-of-Concept (PoC) exploit has been publicly released for a critical vulnerability affecting Oracle WebLogic Server.

3 weeks ago

CERT-In Flags On Oracle Agile PLM Flaw (CVE-2024-21287)

The CERT-In (Computer Emergency Response Team – India) flags CVE-2024-21287 affecting Oracle Agile PLM with high risk of unauthorized access.

2 months ago

Oracle Agile PLM Zero-Day Vulnerability Exploited In The Wild

Oracle has issued an urgent security alert regarding a critical vulnerability in its Agile Product Lifecycle Management (PLM) Framework that is actively being exploited in the wild.

2 months ago

Oracle Warns of Agile PLM Vulnerability Currently Under Active Exploitation

Critical flaw CVE-2024-21287 in Oracle Agile PLM allows unauthenticated file leaks; urgent patch advised.

2 months ago

Oracle Patches Exploited Agile PLM Zero-Day

Oracle has patched a high-severity information disclosure zero-day in Agile PLM that has been exploited in the wild.

2 months ago

Oracle warns of Agile PLM file disclosure flaw exploited in attacks

Oracle has fixed an unauthenticated file disclosure flaw inΒ Oracle Agile Product Lifecycle Management (PLM) tracked as CVE-2024-21287, which was actively exploited as a zero-day to download files.

2 months ago

Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287) - Help Net Security

Oracle has released a critical security patch for CVE-2024-21287, a remotely exploitable flaw in its Agile PLM Framework.

2 months ago

Oracle WebLogic Server Vulnerability Allows Complete Server Take Over

This vulnerability, disclosed on July 17, 2024, allows unauthenticated attackers with network access via T3 and IIOP protocols to gain complete control over the server.

6 months ago

SANS ISC Stormcast: Daily Network Security News Summary; Cyber Security Podcast

Daily Cyber Security News Podcast, Author: Dr. Johannes B. Ullrich

8 months ago

ISC StormCast for Wednesday, May 8th, 2024

Detecting XFinity/Comcast DNS Spoofing https://isc.sans.edu/diary/Detecting%20XFinity%20Comcast%20DNS%20Spoofing/30898 Weblogic PoC CVE-2024-21006 https://pwnull.github.io/2024/oracle%20weblogic%20CVE-2024-21006%20Double-JNDInjection%20RCE%20analyze/ https://github.com/momika233/CVE-2024-21006 PDF...

8 months ago

Threat Intel Roundup: Cisco, Virtualbox, SSLoad, V8 – Threat Radar Intelligence

admin April 23, 2024 No Comments Week in Overview(16 Apr-23 Apr) – 2024 Technical Summary Cisco...

9 months ago

PoC Exploit Released For Critical Oracle VirtualBox Vulnerability

Oracle Virtualbox was identified and reported with a critical vulnerability which was associated with Privilege Escalation and

9 months ago

CVE-2024-21006 Archives - NSFOCUS, Inc., a global network and cyber security leader, protects enterprises and carriers from advanced cyber attacks.

WebLogic T3/IIOP Information Disclosure Vulnerability (CVE-2024-21006/CVE-2024-21007) April 18, 2024 Overview Recently, NSFOCUS CERT detected that Oracle has released a security announcement and fixed...

9 months ago

πŸ’€ Exploit for CVE-2024-20931

Exploit for CVE-2024-20931 | Sploitus | Exploit & Hacktool Search Engine

11 months ago

Alert: Active Exploitation of TP-Link, Apache, and Oracle Vulnerabilities Detected

Heads up, everyone! CISA has issued an advisory warning of active exploitation of three known vulnerabilities.

2 years ago

CISA Warns of Attacks Exploiting Oracle WebLogic Vulnerability Patched in January

CISA warns of attacks exploiting an Oracle WebLogic vulnerability tracked as CVE-2023-21839, which was patched with the January 2023 CPU.

2 years ago