ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Oracle patches exploited Agile PLM vulnerability (CVE-2024-21287)

criticalVulnerability exploited in the wildimportance 60CVE-2024-21287

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21287
Incorrect Authorization Flaw in Oracle Agile PLM 9.3.6 Under Active Exploitation

CVE-2024-21287 is an incorrect authorization flaw (CWE-863) in the Software Development Kit and Process Extension components of the Oracle Agile PLM Framework, part of Oracle's Supply Chain portfolio. An unauthenticated attacker with network access via HTTP can exploit it with low attack complexity and no user interaction. Successful attacks allow unauthorized access to critical data, or potentially complete access to all data accessible through Agile PLM; the impact is confidentiality only (no integrity or availability impact). Only the supported release 9.3.6 of the Agile PLM Framework is listed as affected. The flaw is being actively exploited in the wild: Oracle has warned of active exploitation and shipped a patch, and CISA added it to the Known Exploited Vulnerabilities catalog on November 21, 2024.

Do: Upgrade Agile PLM Framework 9.3.6 using the fix published in Oracle's Critical Patch Update advisory for this CVE, prioritizing instances reachable over HTTP. Because the flaw is under active exploitation, restrict network access to Agile PLM servers and review access logs for signs of unauthorized data reads. If patching is not immediately possible, follow CISA's required action: apply vendor mitigations or discontinue use of the product.

7.52% KEV
  • Oracle Agile Product Lifecycle Management (PLM) Framework - Software Development Kit / Process Extension component 9.3.6
moderate~1,000-10,000 enterprise deployments (plausibly tens of thousands of users); the share exposed to the internet is likely a small fraction
Full article284 words · extracted from helpnetsecurity.com · click to collapse

Oracle has released a security patch for CVE-2024-21287, a remotely exploitable vulnerability in the Oracle Agile PLM Framework that is, according to Tenable researchers, being actively exploited by attackers.

CVE-2024-21287

About CVE-2024-21287

Oracle Agile PLM Framework is an enterprise product lifecycle management solution that enables collaboration between the various teams involved.

CVE-2024-21287 affects version 9.3.6 of the Agile PLM Framework – more specifically, the Agile Software Development Kit and the Process Extension components.

“This vulnerability is remotely exploitable [via HTTP and HTTPS protocol] without authentication, i.e., it may be exploited over a network without the need for a username and password. If successfully exploited, this vulnerability may result in file disclosure,” Oracle shared in the associated advisory.

The NVD entry for the vulnerability details that “successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data”.

CrowdStrike’s researchers Joel Snape and Lutz Wolf have been credited with reporting the flaw.

Exploitation

Tenable Research’s threat landscape status says that “in the wild exploitation has been observed”.

“Oracle strongly recommends that customers apply the updates provided by this Security Alert as soon as possible,” the company said, but did not mention the vulnerability being leveraged by attackers.

We’ve asked for more details from Oracle, Tenable and Crowdstrike and we’ll update this article if we receive a relevant reply.

UPDATE (November 19, 2024, 11:55 a.m. ET):

In a separate post, Eric Maurice, VP of Security Assurance at Oracle, said the vulnerability “was reported as being actively exploited ‘in the wild’ by CrowdStrike”.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/11/19/cve-2024-21287/