peter bassill · operator
$ cve CVE-2024-21287 JSON

CVE-2024-21287 KEV

7.5
HIGH · CVSS 3.1 · EPSS 1.7% (pctl 77)

Patch first

On CISA KEV — known exploited in the wild, due 2024-12-12.

Description

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS1.72% — more likely to be exploited than 77% of all CVEs
WeaknessCWE-863
On CISA KEVyes — remediate by 2024-12-12
Public exploitnone known
Published2024-11-18
Last modified2026-06-17

CISA KEV

NameOracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability
Added2024-11-21
Due2024-12-12
Vendor / productOracle / Agile Product Lifecycle Management (PLM)
Ransomware usenone reported

Affected (1)

VendorProduct
oracleagile product lifecycle management

References

→ the Explorer  ·  watch your stack  ·  NVD