Vulnerability record · CVE-2024-21287 · published 18 November 2024
CVE-2024-21287: Oracle Agile PLM Framework incorrect authorization exposes data
Oracle · Agile Product Lifecycle Management
Oracle Agile PLM Framework 9.3.6 contains an incorrect authorization flaw in the Software Development Kit / Process Extension component. An unauthenticated network attacker can reach it over HTTP and read data they should not be able to access. Because the product holds supply chain and product lifecycle records, exposure of that data is a direct confidentiality problem.
Description
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityCVSS 7.5 with no authentication or user interaction required, plus confirmed CISA KEV listing, makes this a high-priority exposure despite the confidentiality-only impact.
What it is
Oracle Agile PLM Framework 9.3.6 contains an incorrect authorization flaw in the Software Development Kit / Process Extension component. An unauthenticated network attacker can reach it over HTTP and read data they should not be able to access. Because the product holds supply chain and product lifecycle records, exposure of that data is a direct confidentiality problem.
Impact
An attacker gains unauthorized read access to critical data, up to all data accessible through Oracle Agile PLM Framework. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network via HTTP with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N). Any host exposing the affected Agile PLM Framework component is in scope.
Exploitation
CVE-2024-21287 is listed in CISA KEV with a remediation due date of 2024-12-12, indicating known exploitation. EPSS 30-day probability is about 1.7 percent (76th percentile), and no ransomware campaign use is recorded.
What to do
- Apply the Oracle security alert fix for CVE-2024-21287 on Agile PLM Framework 9.3.6, or follow Oracle's stated mitigations if patching is not immediately possible.
- If no mitigation is available, discontinue use of the affected component as CISA directs.
- Restrict network access to the Agile PLM Framework SDK and Process Extension endpoints to trusted hosts only.
- Monitor and log HTTP requests to those endpoints for anomalous or unauthenticated access patterns.
Detection
- Review HTTP access logs for unauthenticated requests to Agile PLM Framework SDK and Process Extension paths.
- Alert on large or unusual data retrieval volumes from Agile PLM Framework by single source IPs.
- Hunt for scanning or enumeration activity against Agile PLM Framework endpoints from external or unexpected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-21287 to the Known Exploited Vulnerabilities catalog on 21 November 2024 as "Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 12 December 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/alert-cve-2024-21287.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-21287 | US Government Resource |
Track CVE-2024-21287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-21287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.