EXPOSURES › CVE-2024-21287
CVE-2024-21287
HIGH ⌖ ON CISA KEV · EXPLOITEDOracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.
This vulnerability enables unauthenticated access to files within the Oracle Agile PLM Software Development Kit, posing a significant risk to DIB organizations relying on Oracle PLM for secure supply chain management. While not an RCE, the exposure of sensitive files could lead to data breaches and compliance violations under FedRAMP/NIST 800-171. Organizations should immediately patch the Process Extension component and audit access controls.
Shame score — A known authorization flaw in a widely used PLM tool that allows unauthenticated file disclosure, though not directly linked to ransomware.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |