ZeroHour

CVE-2024-21287

KEVmoderate1

Incorrect Authorization Flaw in Oracle Agile PLM 9.3.6 Under Active Exploitation

CISA: Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

CVSS 3.1
7.5 high
EPSS
2%p76
Published
()
KEV added
AI analysis

CVE-2024-21287 is an incorrect authorization flaw (CWE-863) in the Software Development Kit and Process Extension components of the Oracle Agile PLM Framework, part of Oracle's Supply Chain portfolio. An unauthenticated attacker with network access via HTTP can exploit it with low attack complexity and no user interaction. Successful attacks allow unauthorized access to critical data, or potentially complete access to all data accessible through Agile PLM; the impact is confidentiality only (no integrity or availability impact). Only the supported release 9.3.6 of the Agile PLM Framework is listed as affected. The flaw is being actively exploited in the wild: Oracle has warned of active exploitation and shipped a patch, and CISA added it to the Known Exploited Vulnerabilities catalog on November 21, 2024.

What to do: Upgrade Agile PLM Framework 9.3.6 using the fix published in Oracle's Critical Patch Update advisory for this CVE, prioritizing instances reachable over HTTP. Because the flaw is under active exploitation, restrict network access to Agile PLM servers and review access logs for signs of unauthorized data reads. If patching is not immediately possible, follow CISA's required action: apply vendor mitigations or discontinue use of the product.

Affected
Oracle Agile Product Lifecycle Management (PLM) Framework - Software Development Kit / Process Extension component9.3.6
Estimated exposure
moderate~1,000-10,000 enterprise deployments (plausibly tens of thousands of users); the share exposed to the internet is likely a small fraction — Oracle Agile PLM is a niche enterprise PLM suite used mainly by large manufacturers with on-premises deployments; with no public install counts or scan data in evidence, this order-of-magnitude estimate is based on the product's limited…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CISA Known Exploited Vulnerability
Affected
Oracle Agile Product Lifecycle Management (PLM)
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
oracle
Products
agile product lifecycle management
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news