Oracle Agile PLM Framework Vulnerability Affects 9.3.6 Version
CVE-2024-21287
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 18 November 2024
Badges
Summary
CVE-2024-21287 is a critical vulnerability in the Oracle Agile PLM Framework affecting version 9.3.6. The flaw allows for unauthorized access to sensitive data and file disclosure, with a high CVSS score of 7.5. The vulnerability has been actively exploited in the wild, potentially allowing threat actors to download files from targeted systems. It was discovered by security researchers from CrowdStrike, and Oracle has urged users to apply the latest patches for protection. The impact of exploitation could lead to unauthorized access to critical data, emphasizing the need for swift mitigation measures. While it's unclear who the perpetrators are and their targets, the urgency of addressing this issue is highlighted by the active exploitation and potential for significant impact.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Oracle Agile PLM Framework 9.3.6
Get notified when SecurityVulnerability.io launches alerting ๐
Well keep you posted ๐ง
News Articles
CERT-In Flags On Oracle Agile PLM Flaw (CVE-2024-21287)
The CERT-In (Computer Emergency Response Team โ India) flags CVE-2024-21287 affecting Oracle Agile PLM with high risk of unauthorized access.
2 months ago
Oracle Agile PLM Zero-Day Vulnerability Exploited In The Wild
Oracle has issued an urgent security alert regarding a critical vulnerability in its Agile Product Lifecycle Management (PLM) Framework that is actively being exploited in the wild.
3 months ago
Oracle Warns of Agile PLM Vulnerability Currently Under Active Exploitation
Critical flaw CVE-2024-21287 in Oracle Agile PLM allows unauthenticated file leaks; urgent patch advised.
3 months ago
References
CVSS V3.1
Timeline
- ๐ฆ
CISA Reported
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by Help Net Security
Vulnerability published