Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 4 min 109 bronnen 3 kritiek 21 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2024-21287

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-863

Beschrijving NL

Oracle Agile Product Lifecycle Management (PLM) bevat een onjuiste autorisatiekwetsbaarheid in de Process Extension-component van de Software Development Kit. Succesvolle exploitatie van deze kwetsbaarheid kan leiden tot niet-geverifieerde openbaarmaking van bestanden.

Vereiste actie: pas mitigaties toe volgens de instructies van de leverancier of stop het gebruik van het product als mitigaties niet beschikbaar zijn.

Origineel (Engels) tonen

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Vendors

Oracle

Affected products

Agile Product Lifecycle Management (plm)

References