CrowdSec
8/10CrowdSec Score

Retail xstore office - Path Traversal (CVE-2024-21136)

Published on16-07-2024
First seen on20-05-2025

116Exploiting IPs reported

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change).

CrowdSec analysis

CVE-2024-21136 is a security vulnerability in Oracle Retail Xstore Office that allows unauthenticated remote attackers to compromise the system through a path traversal issue, potentially impacting the confidentiality and integrity of affected environments.

CrowdSec has been tracking this vulnerability and its exploits since 20th of May 2025.

Insights from the CrowdSec network reveal that the attackers trying to exploit CVE-2024-21136 are composed of a fairly even mix of opportunistic and targeted actors. Some attackers employ preliminary reconnaissance, while others use indiscriminate scanning. Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2024-21136 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2024-21136 is currently experiencing high visibility and active exploitation across the internet.

Exploitation attempts typically involve requests to URLs containing /xstoremgwt/cheetahimages and abusing crafted path traversal payloads within parameters.

Exploitation

Get real-time information about exploitation attempts and actors involved.

Detected IPs

Discover the IPs that targeted this vulnerability across the CrowdSec Network.

Protection

Find out relevant information to protect your stack against this CVE.

Blocklist

With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.

To increase your protection against this CVE, block exploitation attempts with this list of identified actors.