Oracle Agile PLM Framework Vulnerability Affects 9.3.6 Version
Key Information
- Vendor
- Oracle
- Status
- Oracle Agile Plm Framework
- Vendor
- CVE Published:
- 18 November 2024
Badges
Summary
CVE-2024-21287 is a critical vulnerability in the Oracle Agile PLM Framework affecting version 9.3.6. The flaw allows for unauthorized access to sensitive data and file disclosure, with a high CVSS score of 7.5. The vulnerability has been actively exploited in the wild, potentially allowing threat actors to download files from targeted systems. It was discovered by security researchers from CrowdStrike, and Oracle has urged users to apply the latest patches for protection. The impact of exploitation could lead to unauthorized access to critical data, emphasizing the need for swift mitigation measures. While it's unclear who the perpetrators are and their targets, the urgency of addressing this issue is highlighted by the active exploitation and potential for significant impact.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2024-21287 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Oracle Agile PLM Framework = 9.3.6
News Articles
Oracle Warns of Agile PLM Vulnerability Currently Under Active Exploitation
Critical flaw CVE-2024-21287 in Oracle Agile PLM allows unauthenticated file leaks; urgent patch advised.
3 days ago
Oracle Patches Exploited Agile PLM Zero-Day
Oracle has patched a high-severity information disclosure zero-day in Agile PLM that has been exploited in the wild.
4 days ago
Oracle warns of Agile PLM file disclosure flaw exploited in attacks
Oracle has fixed an unauthenticated file disclosure flaw in Oracle Agile Product Lifecycle Management (PLM) tracked as CVE-2024-21287, which was actively exploited as a zero-day to download files.
4 days ago
CVSS V3.1
Timeline
- 👾
Exploit exists.
First article discovered by Help Net Security
Vulnerability published.