← Vulnerability feed

Vulnerability record · CVE-2024-20953 · published 17 February 2024

CVE-2024-20953: Oracle Agile PLM Export deserialization allows takeover

Oracle · Agile Product Lifecycle Management

Oracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network access can exploit it to fully compromise the application, affecting confidentiality, integrity and availability.

8.8 CVSS 3.1 High CISA KEV since 24 Feb 2025 EPSS 3.9% · top 10.0% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score
3.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 with low-privileged network exploitation and confirmed inclusion in CISA KEV make this a high-priority patching target despite a moderate EPSS score.

What it is

Oracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network access can exploit it to fully compromise the application, affecting confidentiality, integrity and availability.

Impact

Successful exploitation results in complete takeover of the Oracle Agile PLM instance, giving the attacker control over application data and functions.

Attack surface

Reachable over HTTP by a low-privileged authenticated attacker; no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N).

Exploitation

CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-24 with a remediation due date of 2025-03-17, indicating active exploitation. EPSS 30-day probability is about 3.9 percent (89.8th percentile); no ransomware campaign use is recorded.

What to do

  • Apply the Oracle Critical Patch Update (January 2024) fix for Agile PLM 9.3.6 or upgrade to a supported release.
  • If patching is not possible, restrict network access to the Agile PLM Export component and follow CISA's required action to discontinue use if no mitigation exists.
  • Enforce least privilege and review accounts with low-privileged access that can reach the Export functionality.
  • Monitor and limit HTTP access to the Agile PLM application from untrusted networks.

Detection

  • Review Agile PLM application and web server logs for unusual Export component requests, especially from low-privileged accounts.
  • Look for signs of deserialization abuse such as unexpected Java object payloads or anomalous process behavior on the Agile PLM host.
  • Correlate network traffic to the Agile PLM HTTP endpoint with post-exploitation activity like new accounts or data exfiltration.
  • Track CISA KEV status and verify patched versions across all Agile PLM 9.3.6 deployments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-20953 to the Known Exploited Vulnerabilities catalog on 24 February 2025 as "Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 17 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-20953 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed7.5CVE-2024-21287Oracle Agile PLM Framework incorrect authorization exposes dataOracle Agile PLM Framework 9.3.6 contains an incorrect authorization flaw in the Software Development Kit / Process Extension component. An unauthent…KEVEPSS 1.7%analysed9.9CVE-2025-21556Oracle agile product lifecycle management incorrect authorization vulnerabilityVulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is…EPSS 0.64%9.8CVE-2026-71040Oracle agile product lifecycle management improper access control vulnerabilityVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily e…EPSS 0.51%9.8CVE-2026-61167Oracle agile product lifecycle management improper access control vulnerabilityVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily e…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2024-20953), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.