CVE-2024-20953
published 2024-02-17CVE-2024-20953: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable…
PriorityP184high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-03-17
Exploited in the wild
EPSS
3.40%
87.5th percentile
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | agile_product_lifecycle_management | — | — |
| oracle_corporation | agile_plm_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target product and component: Oracle Agile PLM version 9.3.6, Export component — deserialization vulnerability exploitable by low-privileged authenticated users over HTTP ↗
- →Attack vector is network (HTTP), no user interaction required, low privileges sufficient — monitor for unusual HTTP requests to Oracle Agile PLM Export endpoints from authenticated low-privileged accounts, especially those carrying serialized Java object payloads ↗
- →Successful exploitation results in full system takeover (C/I/A all HIGH) — treat any unexpected process spawning or file writes from the Agile PLM application server process as a high-confidence post-exploitation indicator ↗
- ·Only Oracle Agile PLM version 9.3.6 is confirmed affected; other versions are not listed as vulnerable in the advisory ↗
- ·CISA KEV remediation deadline is 2025-03-17; vendor patch details are in the January 2024 Oracle CPU — ensure patch applicability is verified before deployment ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_oracle8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
cisa·2025-02-24·CVSS 8.8
CVE-2024-20953 [HIGH] CWE-502 Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
Vulnerability: Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
Affected: Oracle Agile Product Lifecycle Management (PLM)
Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://www.oracle.com/security-alerts/cpujan2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-20953
Remediation Due Date: 2025-03-17
Oracle
Oracle Oracle Supply Chain Risk Matrix: Export — CVE-2024-20953
vendor_oracle·2024-01-15·CVSS 8.8
CVE-2024-20953 [HIGH] Oracle Oracle Supply Chain Risk Matrix: Export — CVE-2024-20953
Oracle Oracle Supply Chain Risk Matrix: Export vulnerability
CVE: CVE-2024-20953
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
GHSA
GHSA-f4jc-jxp8-5pv7: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export)
ghsa_unreviewed·2024-02-17
CVE-2024-20953 [HIGH] CWE-502 GHSA-f4jc-jxp8-5pv7: Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export)
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
VulnCheck
Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
vulncheck·2024·CVSS 8.8
CVE-2024-20953 [HIGH] CWE-502 Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.
Affected: Oracle Agile Product Lifecycle Management (PLM)
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.crowdstrike.com/explore/2025-global-threat-report; https://www.loginsoft.com/reports/annually/vulnerability-intelligence-report-2025; https://www.gstatic.com/security-marketing/m-trends-2026-en.pdf
Remediation Due: 2025-03-17
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-17
Published
2025-02-24
Added to CISA KEV
Exploited in the wild