Skip to content
COOEY

EXPOSURES › CVE-2024-21287

CVE-2024-21287

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-11-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-21287 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatcheddata-breachauth-bypass

Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.

This vulnerability enables unauthenticated access to files within the Oracle Agile PLM Software Development Kit, posing a significant risk to DIB organizations relying on Oracle PLM for secure supply chain management. While not an RCE, the exposure of sensitive files could lead to data breaches and compliance violations under FedRAMP/NIST 800-171. Organizations should immediately patch the Process Extension component and audit access controls.

Shame score — A known authorization flaw in a widely used PLM tool that allows unauthenticated file disclosure, though not directly linked to ransomware.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.

AFFECTED FEDRAMP PRODUCTS · 10
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized