Oracle Warns of Agile PLM Vulnerability Currently Under Active Exploitation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21287 | Incorrect Authorization Flaw in Oracle Agile PLM 9.3.6 Under Active Exploitation CVE-2024-21287 is an incorrect authorization flaw (CWE-863) in the Software Development Kit and Process Extension components of the Oracle Agile PLM Framework, part of Oracle's Supply Chain portfolio. An unauthenticated attacker with network access via HTTP can exploit it with low attack complexity and no user interaction. Successful attacks allow unauthorized access to critical data, or potentially complete access to all data accessible through Agile PLM; the impact is confidentiality only (no integrity or availability impact). Only the supported release 9.3.6 of the Agile PLM Framework is listed as affected. The flaw is being actively exploited in the wild: Oracle has warned of active exploitation and shipped a patch, and CISA added it to the Known Exploited Vulnerabilities catalog on November 21, 2024. Do: Upgrade Agile PLM Framework 9.3.6 using the fix published in Oracle's Critical Patch Update advisory for this CVE, prioritizing instances reachable over HTTP. Because the flaw is under active exploitation, restrict network access to Agile PLM servers and review access logs for signs of unauthorized data reads. If patching is not immediately possible, follow CISA's required action: apply vendor mitigations or discontinue use of the product. | 7.5 | 2% | KEV |
| moderate~1,000-10,000 enterprise deployments (plausibly tens of thousands of users); the share exposed to the internet is likely a small fraction |
Full article224 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananNov 20, 2024Software Security / Vulnerability
Oracle is warning that a high-severity security flaw impacting the Agile Product Lifecycle Management (PLM) Framework has been exploited in the wild.
The vulnerability, tracked as CVE-2024-21287 (CVSS score: 7.5), could be exploited sans authentication to leak sensitive information.
"This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password," it said in an advisory. "If successfully exploited, this vulnerability may result in file disclosure."
CrowdStrike security researchers Joel Snape and Lutz Wolf have been credited with discovering and reporting the flaw.
There is currently no information available on who is exploiting the vulnerability, the targets of the malicious activity, and how widespread these attacks are.
"If successfully exploited, an unauthenticated perpetrator could download, from the targeted system, files accessible under the privileges used by the PLM application," Eric Maurice, vice president of Security Assurance at Oracle, said.
In light of active exploitation, users are recommended to apply the latest patches as soon as possible for optimal protection.
The Hacker News has reached out to Oracle and CrowdStrike for comment. We will update this story if we get a reply.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/oracle-warns-of-agile-plm-vulnerability.html