Junglewise Threat Intelligence

CVE-2024-20953: Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

CVE-2024-20953 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2025-02-24

Vendors: Oracle.

Executive brief

A deserialization vulnerability in the Export component of Oracle Agile PLM allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can lead to a complete takeover of the Oracle Agile PLM instance.

Affected products

  • Oracle Agile Product Lifecycle Management (PLM) 9.3.6

Timeline

  • 2024-02-16: disclosed: Initial NVD publication and Oracle advisory release.
  • 2025-02-24: kev added: CISA added CVE-2024-20953 to the Known Exploited Vulnerabilities (KEV) catalog.

Related threats