PT-2024-8694 · Oracle · Oracle Agile Plm Framework

Joel Snape

+1

·

Published

2024-11-18

·

Updated

2026-05-03

·

CVE-2024-21287

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Agile PLM Framework version 9.3.6
Description The issue is related to an unauthenticated file disclosure flaw in the Oracle Agile PLM Framework, allowing an attacker to access files without authentication. This vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. The vulnerability is easily exploitable and has been actively exploited in attacks.
Recommendations For Oracle Agile PLM Framework version 9.3.6, urgently upgrade the affected component to mitigate the risk of unauthorized access to critical data. Apply security patches immediately to prevent exploitation of this vulnerability. As a temporary workaround, consider restricting access to sensitive files and data until a patch is applied.

Fix

Incorrect Authorization

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-10296
CVE-2024-21287

Affected Products

Oracle Agile Plm Framework