Home / Vulnerabilities / CVE-2024-21287
HIGH SEVERITY
CVE-2024-21287 Oracle · Agile Product Lifecycle Management (PLM)

Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

Technical Severity

CVSS v3.1 Metrics

HIGH
7.5 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation Likelihood

EPSS Prediction

69.83 %
Predictive Probability
Percentile Rank
98.6 th

Documented as more likely to be exploited than 98.6% of known CVEs.

Detection Date

Nov 21, 2024

Remediation Due

Dec 12, 2024

CISA Catalog Active

Threat Analysis

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.

Remediation Directive

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

External Intelligence