logo

Oracle warns of Agile PLM file disclosure flaw exploited in attacks

ID: 549ef9a4-2bc4-568c-9579-962b47dfe509

STIX ID: report--549ef9a4-2bc4-568c-9579-962b47dfe509

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-19

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Oracle fixed CVE-2024-21287, an unauthenticated file-disclosure vulnerability in Oracle Agile Product Lifecycle Management (PLM) that has been actively exploited in the wild to download files. Oracle rated the issue CVSS 7.5, credited CrowdStrike researchers for disclosure, and strongly urged customers to apply updates immediately to mitigate file disclosure risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.