Junglewise Threat Intelligence

CVE-2024-21287: Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

CVE-2024-21287 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-11-21

Vendors: Oracle.

Executive brief

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. An unauthenticated attacker with network access via HTTP can exploit this to gain unauthorized access to critical data or complete access to all accessible data within the framework.

Affected products

  • Oracle Agile Product Lifecycle Management Framework 9.3.6

Timeline

  • 2024-11-18: disclosed: CVE received from Oracle and published by NVD
  • 2024-11-21: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2024-11-21: exploited: Reported as exploited in the wild

Related threats