ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Adobe ColdFusion and Oracle Agile PLM flaws to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2017-3066CVE-2024-20953CVE-2025-24989

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-3066
Unauthenticated Deserialization RCE in Adobe ColdFusion (BlazeDS)

CVE-2017-3066 is a Java deserialization vulnerability (CWE-502) in the Apache BlazeDS library bundled with Adobe ColdFusion, which handles the product's Flex/AMF remoting functionality. An unauthenticated remote attacker can trigger it by sending crafted serialized Java objects to the server's BlazeDS message broker endpoints over the network. Successful exploitation allows arbitrary code execution with the privileges of the ColdFusion service, and the critical CVSS 3.1 score of 9.8 reflects that no privileges, user interaction, or special conditions are required. Users of Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 Update 11 and earlier, and ColdFusion 10 Update 22 and earlier are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-24 alongside an Oracle flaw, its EPSS probability of exploitation within 30 days is 90.6% (100th percentile), and a public proof-of-concept exploit is available on Exploit-DB (43993).

Do: Update all ColdFusion 10, 11, and 2016 servers beyond the affected update levels per Adobe's vendor guidance, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Until patched, restrict or block network access to the BlazeDS/AMF remoting endpoints (the /flex2gateway endpoints) at the firewall or web server layer, since these are the attack surface for this flaw, and review access logs for anomalous requests to them. A public proof-of-concept (Exploit-DB 43993) shows unauthenticated exploitation, so treat exposed instances as high-priority; ransomware use is currently listed as unknown.

9.891% KEV PoC
  • adobe coldfusion ColdFusion 2016 Update 3 and earlier
  • adobe coldfusion ColdFusion 11 Update 11 and earlier
  • adobe coldfusion ColdFusion 10 Update 22 and earlier
largetens of thousands of internet-exposed ColdFusion servers (10k-100k range)
CVE-2024-20953
Deserialization Flaw in Oracle Agile PLM 9.3.6 Export Component Exploited in the Wild

CVE-2024-20953 is an insecure deserialization vulnerability (CWE-502) in the Export component of Oracle Agile Product Lifecycle Management (PLM), part of Oracle Supply Chain. A low-privileged authenticated attacker can trigger it over HTTP by sending crafted serialized data to the Export functionality; the flaw is easily exploitable and requires no user interaction. Successful exploitation lets the attacker take over the Agile PLM application, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Only Agile PLM 9.3.6 is listed as affected, so organizations running that version — typically enterprises using Agile PLM to manage product lifecycle data — are in scope. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-24, confirming exploitation in the wild, though no public proof-of-concept is known and use in ransomware campaigns is unconfirmed (EPSS: ~3.9% probability of exploitation in 30 days).

Do: Apply the fix Oracle shipped for this CVE in its January 2025 Critical Patch Update for Agile PLM 9.3.6; if patching is delayed, restrict HTTP access to the Export component and apply vendor mitigations per CISA's KEV required action, or discontinue use of the product if mitigations are unavailable. Review HTTP logs and the Export component for signs of exploitation, and audit which low-privileged accounts can reach the application, since only limited credentials are needed to attack it.

8.84% KEV
  • Oracle Agile Product Lifecycle Management (PLM), Export component 9.3.6 (only supported version listed as affected)
nichelikely low thousands of deployments worldwide (estimate; no public install-base counts)
CVE-2025-24989
Access Control Bypass Enables Privilege Escalation in Microsoft Power Pages

CVE-2025-24989 is a critical (CVSS 9.8) improper access control flaw (CWE-284) in Microsoft Power Pages, Microsoft's low-code cloud service for building external-facing websites. An unauthenticated attacker can trigger it over the network by interacting with an affected Power Pages site, bypassing the user registration control and elevating privileges without any prior credentials or user interaction. Successful exploitation grants elevated access with high impact on the confidentiality, integrity, and availability of the affected site. Only organizations using Power Pages are in scope, and Microsoft has already mitigated the vulnerability in the cloud service and directly notified affected customers - if you were not notified, this vulnerability does not affect you. The flaw was actively exploited before and during patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-21, and carries a 1.6% EPSS probability of exploitation in the next 30 days.

Do: No customer patch is required because Microsoft applied the fix service-side; review Microsoft's notification and follow its instructions to inspect your Power Pages sites for signs of exploitation (e.g., unexpected or unauthorized users, unusual privilege changes) and perform the recommended cleanup. Federal agencies must apply the vendor mitigations per CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable. If you were not notified by Microsoft, the vulnerability does not affect you, though reviewing your site's registration settings is a prudent verification step.

9.82% KEV
  • Microsoft Power Pages Cloud service; no specific version numbers disclosed - Microsoft addressed the issue with a service-side mitigation and notified affected customers
largeunknown exact count; plausibly tens of thousands of Power Pages sites/tenants (affected subset undisclosed)
Full article310 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 25, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM) vulnerabilities to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Adobe ColdFusion and Oracle Agile PLM vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

The two vulnerabilities are:

  • CVE-2017-3066 Adobe ColdFusion Deserialization Vulnerability
  • CVE-2024-20953 Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

CVE-2017-3066 (CVSS score of 9.8) is a Java deserialization vulnerability in the Apache BlazeDS library in Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier. An attacker can exploit the vulnerability to achieve arbitrary code execution.

CVE-2024-20953 (CVSS score of 8.8) is a Deserialization Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The flaw affects supported version 9.3.6. A low-privileged attacker with network access via HTTP to compromise Oracle Agile PLM could exploit this vulnerability to takeover Oracle Agile PLM.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by March 24, 2025.

Last week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Microsoft Power Pages vulnerability, tracked as CVE-2025-24989, to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2025-24989 (CVSS score: 8.2) is an improper access control flaw in Power Pages, an unauthorized attacker could exploit the flaw to elevate privileges over a network potentially bypassing the user registration control.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/174613/security/u-s-cisa-adds-adobe-coldfusion-and-oracle-agile-plm-flaws-to-its-known-exploited-vulnerabilities-catalog.html