CVE-2024-21287

ENISA EUVD: EUVD-2024-19000 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 20, 2026 3 articles Published: 2024-11-18

EPSS Score

Source: FIRST.org · 2026-05-23
69.83%
probability
This CVE has a 69.83% probability of being exploited in the next 30 days.
0% Top 98.7th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.5
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

NVD
Vulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Software Development Kit, Process Extension). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Agile PLM Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Affected Products

Oracle Corporation
Oracle Agile PLM Framework
9.3.6

Attack Intelligence

Signal Intelligence

Confidence
85%
EPSS 69.83%
CVSS v3.1 7.5
Mentions 3

CNA Information

CNA Assigner
oracle

Analyst Note

CVE-2024-21287 in Oracle Agile PLM is explicitly documented as actively exploited in the wild (TheHackerNews article 1) and was subsequently added to CISA's Known Exploited Vulnerabilities catalog (article 2), indicating exploitation preceded or coincided with patch availability. The 2024 CVE year and active exploitation reports confirm zero-day status.

Threat Actors 2

APT 28
apt_group Information theft and espionage 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT

Triage Info

Decided atMar 20, 2026
Published DateNov 18, 2024