cbcvebase.
CVE-2024-20953
published 2024-02-17

CVE-2024-20953: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable…

PriorityP184high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-03-17
Exploited in the wild
EPSS
3.40%
87.5th percentile
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Affected

2 ranges
VendorProductVersion rangeFixed in
oracleagile_product_lifecycle_management
oracle_corporationagile_plm_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Target product and component: Oracle Agile PLM version 9.3.6, Export component — deserialization vulnerability exploitable by low-privileged authenticated users over HTTP
  • Attack vector is network (HTTP), no user interaction required, low privileges sufficient — monitor for unusual HTTP requests to Oracle Agile PLM Export endpoints from authenticated low-privileged accounts, especially those carrying serialized Java object payloads
  • Successful exploitation results in full system takeover (C/I/A all HIGH) — treat any unexpected process spawning or file writes from the Agile PLM application server process as a high-confidence post-exploitation indicator
  • ·Only Oracle Agile PLM version 9.3.6 is confirmed affected; other versions are not listed as vulnerable in the advisory
  • ·CISA KEV remediation deadline is 2025-03-17; vendor patch details are in the January 2024 Oracle CPU — ensure patch applicability is verified before deployment

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_oracle8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.