• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    government cyber security

    UK Tightens Government Cyber Security After Cutting Critical Vulnerabilities by 75%

    NIS2 Directive

    National Cyber Security Bill and NIS2: Senior Management’s Compliance Guide

    iphone, ipad, apple devices

    Apple Devices Become First Consumer Products Cleared for NATO Classified Data—But Questions Remain

    OpenClaw Vulnerability

    OpenClaw Vulnerability Exposes How an Open-Source AI Agent Can Be Hijacked

    space cyber security

    India Strengthens Space Cyber Security with New CERT-In and SIA-India Framework

    cybersecurity threats of 2026

    Samsung SDS Identifies Top Cybersecurity Threats of 2026 as AI Risks Escalate

    CISCO SD-WAN, Cisco, SD-WAN, CISA, ASD, Zero-Day

    Hackers Exploited Cisco SD-WAN Zero-Day for Three Years Before Detection

    Hazeldenes cyberattack

    Australian Poultry Giant Hazeldenes Faces Operational Disruption After Cyberattack

    age verification technologies

    FTC Clarifies COPPA Stance, Backs Age Verification Technologies for Platforms

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    government cyber security

    UK Tightens Government Cyber Security After Cutting Critical Vulnerabilities by 75%

    iphone, ipad, apple devices

    Apple Devices Become First Consumer Products Cleared for NATO Classified Data—But Questions Remain

    space cyber security

    India Strengthens Space Cyber Security with New CERT-In and SIA-India Framework

    CISCO SD-WAN, Cisco, SD-WAN, CISA, ASD, Zero-Day

    Hackers Exploited Cisco SD-WAN Zero-Day for Three Years Before Detection

    age verification technologies

    FTC Clarifies COPPA Stance, Backs Age Verification Technologies for Platforms

    scam centers in Southeast Asia

    Scam Centers in Southeast Asia Drive Billion-Dollar Losses: FBI

    Digital Services Act

    X vs EU: Platform Appeals Against €120M Digital Services Act Penalty

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    French National Bank Authority, FICOBA, CNIL

    French National Bank Authority Breach Exposed 1.2 Million Accounts

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    government cyber security

    UK Tightens Government Cyber Security After Cutting Critical Vulnerabilities by 75%

    NIS2 Directive

    National Cyber Security Bill and NIS2: Senior Management’s Compliance Guide

    iphone, ipad, apple devices

    Apple Devices Become First Consumer Products Cleared for NATO Classified Data—But Questions Remain

    OpenClaw Vulnerability

    OpenClaw Vulnerability Exposes How an Open-Source AI Agent Can Be Hijacked

    space cyber security

    India Strengthens Space Cyber Security with New CERT-In and SIA-India Framework

    cybersecurity threats of 2026

    Samsung SDS Identifies Top Cybersecurity Threats of 2026 as AI Risks Escalate

    CISCO SD-WAN, Cisco, SD-WAN, CISA, ASD, Zero-Day

    Hackers Exploited Cisco SD-WAN Zero-Day for Three Years Before Detection

    Hazeldenes cyberattack

    Australian Poultry Giant Hazeldenes Faces Operational Disruption After Cyberattack

    age verification technologies

    FTC Clarifies COPPA Stance, Backs Age Verification Technologies for Platforms

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    government cyber security

    UK Tightens Government Cyber Security After Cutting Critical Vulnerabilities by 75%

    iphone, ipad, apple devices

    Apple Devices Become First Consumer Products Cleared for NATO Classified Data—But Questions Remain

    space cyber security

    India Strengthens Space Cyber Security with New CERT-In and SIA-India Framework

    CISCO SD-WAN, Cisco, SD-WAN, CISA, ASD, Zero-Day

    Hackers Exploited Cisco SD-WAN Zero-Day for Three Years Before Detection

    age verification technologies

    FTC Clarifies COPPA Stance, Backs Age Verification Technologies for Platforms

    scam centers in Southeast Asia

    Scam Centers in Southeast Asia Drive Billion-Dollar Losses: FBI

    Digital Services Act

    X vs EU: Platform Appeals Against €120M Digital Services Act Penalty

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    French National Bank Authority, FICOBA, CNIL

    French National Bank Authority Breach Exposed 1.2 Million Accounts

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Critical Flaw in Oracle Agile PLM Framework Exposes Sensitive Data: Patch Now

Ashish Khaitan by Ashish Khaitan
November 28, 2024
in Firewall Daily, Cyber News, Vulnerabilities
0
CVE-2024-21287
769
SHARES
4.3k
VIEWS
Share on LinkedInShare on Twitter

Oracle’s Agile Product Lifecycle Management (PLM) software has been flagged for a security vulnerability (CVE-2024-21287) by CERT-In (Computer Emergency Response Team – India). The vulnerability, cataloged as CIVN-2024-0350, was identified on November 26, 2024, and is classified as a High risk threat. 

This CVE-2024-21287 vulnerability affects the Oracle Agile PLM Framework version 9.3.6, a product widely used by organizations to manage product lifecycles, streamline development processes, and improve collaboration. 

What is the Oracle Agile PLM Vulnerability (CVE-2024-21287)? 

The vulnerability, categorized as an Information Disclosure Vulnerability, could potentially allow an authenticated remote attacker to gain unauthorized access to sensitive data stored in Oracle Agile PLM systems. If successfully exploited, the flaw could lead to the exposure of critical system information, placing organizations at heightened risk of data breaches, intellectual property theft, or unauthorized manipulation of PLM data. 

security vulnerability (CVE-2024-21287)
Cert-IN Flags security vulnerability CVE-2024-21287 (Source: Cert-IN)

Oracle Agile PLM is a key component of Oracle Supply Chain, which facilitates the management of product design, quality, and compliance. The vulnerability is tied to improper authentication within the PLM framework, allowing an attacker to exploit the system via an HTTP connection. This means an attacker can access sensitive information or compromise the entire Oracle Agile PLM system remotely. 

Severity and Impact of the Vulnerability 

CERT-In’s advisory highlights the potential for data exfiltration as one of the most alarming consequences of this vulnerability. By exploiting the CVE-2024-21287 flaw, malicious actors could extract confidential information, which could then be used for financial gain, industrial espionage, or to sabotage operations. 

The high severity rating assigned to this vulnerability is due to its ability to bypass authentication protocols, making it remotely exploitable without requiring the attacker to have valid user credentials. This increases the likelihood that attackers, particularly those targeting enterprise data and critical systems, could successfully exploit this flaw. 

report-ad-banner

Exploitation and Risk to End-User Organizations 

The primary audience for this warning includes all organizations utilizing Oracle Agile PLM in their PLM workflows. The risk is particularly significant for businesses relying on Oracle Agile for managing product development and supply chain operations, where the confidentiality and integrity of product-related data are critical. 

Exploitation of this vulnerability would allow attackers to view or manipulate sensitive files, impacting not only the security of product information but also the stability of the entire product lifecycle management process. Sensitive documents related to product design, specifications, and even intellectual property could be exposed to external threats. 

Oracle’s Response and Patch Availability 

Oracle has issued a security alert and strongly recommends that customers update their systems to Oracle Agile PLM Framework version 9.3.6 with the latest security patches. These patches are crucial for addressing the Information Disclosure Vulnerability identified in the framework and preventing unauthorized access or data leaks. 

Oracle’s advisory outlines the importance of applying the security updates immediately to mitigate any risk associated with this vulnerability. While Oracle encourages all users to upgrade to supported versions of Agile PLM, they note that unsupported versions may still be vulnerable, and users are advised to seek guidance on upgrading to supported releases. 

CVE-2024-21287 and CVSS Scoring 

The vulnerability is cataloged as CVE-2024-21287 and is rated using the Common Vulnerability Scoring System (CVSS) version 3.1. The CVSS base score of 7.5 reflects the seriousness of this vulnerability, with a High level of risk. Key details of the vulnerability are as follows: 

  • Attack Vector: Network-based (can be exploited over HTTP) 
  • Access Requirements: No authentication required (remotely exploitable) 
  • Confidentiality Impact: High 
  • Integrity Impact: None 
  • Availability Impact: None 

This security flaw primarily impacts Oracle Agile PLM Framework’s Software Development Kit (SDK) and Process Extension, components integral to the PLM solution. As per the CVSS scoring, the attack vector involves low complexity, meaning that it does not require specialized knowledge or extensive technical expertise to exploit. 

Conclusion 

Organizations using the Oracle Agile Product Lifecycle Management should install the latest patches.  As this flaw impacts versions under Oracle’s Premier Support and Extended Support, upgrading to supported releases is crucial for protecting sensitive PLM data.  

By staying current with Oracle’s updates and enhancing security protocols, such as implementing multi-factor authentication and network monitoring, businesses can minimize the risks and ensure the long-term stability of their PLM systems. 

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: CIVN-2024-0350CVE-2024-21287Oracle Agile PLM FrameworkOracle Agile PLM VulnerabilityThe Cyber ExpressThe Cyber Express News
Previous Post

Verizon, AT&T Targeted by Second Threat Actor Who Claims Trump, Harris Call Logs

Next Post

Australia’s New Cyber Security Act: Mandatory Ransom Payment Reporting

Next Post
Cyber Security Act

Australia's New Cyber Security Act: Mandatory Ransom Payment Reporting

Threat Landscape Reports 2025

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

government cyber security
Cyber News

UK Tightens Government Cyber Security After Cutting Critical Vulnerabilities by 75%

February 27, 2026
NIS2 Directive
Firewall Daily

National Cyber Security Bill and NIS2: Senior Management’s Compliance Guide

February 27, 2026
iphone, ipad, apple devices
Cyber Essentials

Apple Devices Become First Consumer Products Cleared for NATO Classified Data—But Questions Remain

February 27, 2026
OpenClaw Vulnerability
Firewall Daily

OpenClaw Vulnerability Exposes How an Open-Source AI Agent Can Be Hijacked

February 27, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information