CrowdSec
6/10CrowdSec Score

Retail xstore office - Path Traversal (CVE-2024-21136)

Published on16-07-2024
First seen on20-05-2025

146Exploiting IPs reported

Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change).

CrowdSec analysis

CVE-2024-21136 is a security vulnerability in Oracle Retail Xstore Office that allows unauthenticated remote attackers to compromise the system through a path traversal issue, potentially impacting the confidentiality and integrity of affected environments.

CrowdSec has been tracking this vulnerability and its exploits since 20th of May 2025.

Insights from the CrowdSec network reveal that the attackers trying to exploit CVE-2024-21136 are composed of a fairly even mix of opportunistic and targeted actors. Some attackers employ preliminary reconnaissance, while others use indiscriminate scanning. Telemetry from the CrowdSec network also shows that exploitation activity for CVE-2024-21136 remains steady week-over-week. Attack volumes are consistent with long-term trends, indicating sustained interest from threat actors. CVE-2024-21136 continues to be an active part of the threat landscape and will likely remain this way for the forseeable future.

Exploitation attempts typically involve requests to URLs containing /xstoremgwt/cheetahimages and abusing crafted path traversal payloads within parameters.

Exploitation

Get real-time information about exploitation attempts and actors involved.

Detected IPs

Discover the IPs that targeted this vulnerability across the CrowdSec Network.

Protection

Find out relevant information to protect your stack against this CVE.

Blocklist

With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.

To increase your protection against this CVE, block exploitation attempts with this list of identified actors.