Retail xstore office - Path Traversal (CVE-2024-21136)
116Exploiting IPs reported
Vulnerability in the Oracle Retail Xstore Office product of Oracle Retail Applications (component: Security). Supported versions that are affected are 19.0.5, 20.0.3, 20.0.4, 22.0.0 and 23.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Office. While the vulnerability is in Oracle Retail Xstore Office, attacks may significantly impact additional products (scope change).
CrowdSec analysis
CVE-2024-21136 is a security vulnerability in Oracle Retail Xstore Office that allows unauthenticated remote attackers to compromise the system through a path traversal issue, potentially impacting the confidentiality and integrity of affected environments.
CrowdSec has been tracking this vulnerability and its exploits since 20th of May 2025.
Insights from the CrowdSec network reveal that the attackers trying to exploit CVE-2024-21136 are composed of a fairly even mix of opportunistic and targeted actors. Some attackers employ preliminary reconnaissance, while others use indiscriminate scanning. Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2024-21136 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2024-21136 is currently experiencing high visibility and active exploitation across the internet.
Exploitation attempts typically involve requests to URLs containing /xstoremgwt/cheetahimages
and abusing crafted path traversal payloads within parameters.
Exploitation
Get real-time information about exploitation attempts and actors involved.
Protection
Find out relevant information to protect your stack against this CVE.
Blocklist
With our advanced worldwide network detection, CrowdSec can provide a list of IPs known for exploiting the vulnerability.
To increase your protection against this CVE, block exploitation attempts with this list of identified actors.