CVE-2024-20953
KEVnicheDeserialization Flaw in Oracle Agile PLM 9.3.6 Export Component Exploited in the Wild
CISA: Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability
CVE-2024-20953 is an insecure deserialization vulnerability (CWE-502) in the Export component of Oracle Agile Product Lifecycle Management (PLM), part of Oracle Supply Chain. A low-privileged authenticated attacker can trigger it over HTTP by sending crafted serialized data to the Export functionality; the flaw is easily exploitable and requires no user interaction. Successful exploitation lets the attacker take over the Agile PLM application, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Only Agile PLM 9.3.6 is listed as affected, so organizations running that version — typically enterprises using Agile PLM to manage product lifecycle data — are in scope. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-24, confirming exploitation in the wild, though no public proof-of-concept is known and use in ransomware campaigns is unconfirmed (EPSS: ~3.9% probability of exploitation in 30 days).
What to do: Apply the fix Oracle shipped for this CVE in its January 2025 Critical Patch Update for Agile PLM 9.3.6; if patching is delayed, restrict HTTP access to the Export component and apply vendor mitigations per CISA's KEV required action, or discontinue use of the product if mitigations are unavailable. Review HTTP logs and the Export component for signs of exploitation, and audit which low-privileged accounts can reach the application, since only limited credentials are needed to attack it.
| Oracle Agile Product Lifecycle Management (PLM), Export component | 9.3.6 (only supported version listed as affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
- Affected
- Oracle Agile Product Lifecycle Management (PLM)
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- oracle
- Products
- agile product lifecycle management
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H