CVE-2024-21287Active Exploitation(oracle / agile_product_lifecycle_management)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for oracle agile_product_lifecycle_management systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

5.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-12-12. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-863

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • agile_product_lifecycle_management

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 3 mentions (2026-05-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
agile_product_lifecycle_management

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-03: 3Mentions · 2026-06-13: 1PoC Mentioned / Linked · 2026-06-13: 1Active Exploitation · 2026-05-03: 3Active Exploitation · 2026-06-13: 1Technical Details · 2026-06-13: 105-0306-13
Signal classification1 categories
Active Exploitation
4100.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-05-033
Active Exploitation3
2026-06-131
Active Exploitation1
Full discourse4 posts
  • Orizon@OrizonCyber
    Active Exploitation

    CVE-2024-21287 lets attackers bypass auth in Oracle's WebLogic Server. Zero-click RCE through deserialization flaws. ShinyHunters already weaponized it — scanning for unpatched .edu domains since last week. How many student SSNs before CISOs wake up?

    Post summary

    CVE‑2024‑21287 is a zero‑click RCE that allows authentication bypass in Oracle WebLogic. ShinyHunters have weaponized it and are actively scanning unpatched .edu domains.

    10000173
    59 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2024-21287 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-21, indicating active exploitation in the wild CISA KEV.

    Post summary

    CISA has added CVE-2024-21287 to its KEV catalog, confirming it is being actively exploited in the wild.

    1000030
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-21287. What happened CISA added CVE-2024-21287 to the Known Exploited Vulnerabilities (KEV) catalog on 2024-11-21, indicating active exploitation in the wild CISA KEV.

    Post summary

    CISA has added CVE-2024-21287 to its KEV catalog, confirming that the vulnerability is actively exploited in the wild.

    1000030
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-21287-agile-product-lifecycle-management-plm #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link title indicates that CVE-2024-21287 is reportedly actively exploited in Agile PLM, though the text does not provide concrete details or code.

    0000023
    152 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporacleagile_product_lifecycle_management9.3.6--

Explore more