Oracle has released patches for a high-severity information disclosure vulnerability in Agile Product Lifecycle Management (PLM), which has been actively exploited in the wild. The flaw, tracked as CVE-2024-21287, has a CVSS score of 7.5 and affects Agile PLM version 9.3.6. This zero-day vulnerability allows remote, unauthenticated attackers to exploit the system without needing any credentials. According to Oracle, if successfully exploited, the vulnerability could allow attackers to download files accessible under the privileges used by the PLM application. This could potentially expose sensitive data or give attackers full access to the data within the Agile PLM framework. The company has credited Joel Snape and Lutz Wolf of CrowdStrike for discovering the flaw, and Oracle’s VP of security assurance, Eric Maurice, confirmed that the vulnerability has been observed in active exploitation. Oracle urges users to apply the patches provided in their advisory to mitigate the risk. Agile PLM, introduced around 20 years ago, offers organizations tools for managing product data and collaborating across teams. Despite its usefulness, Oracle announced in April 2024 that it would end premier support for Agile PLM by December 31, 2027. Oracle and CrowdStrike have not yet released detailed technical information about the vulnerability or the specifics of the in-the-wild exploitation, and inquiries have been made for further details.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...