Vulnerability record · CVE-2024-20953 · published 17 February 2024
CVE-2024-20953: Oracle Agile PLM Export deserialization allows takeover
Oracle · Agile Product Lifecycle Management
Oracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network access can exploit it to fully compromise the application, affecting confidentiality, integrity and availability.
Description
Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with low-privileged network exploitation and confirmed inclusion in CISA KEV make this a high-priority patching target despite a moderate EPSS score.
What it is
Oracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network access can exploit it to fully compromise the application, affecting confidentiality, integrity and availability.
Impact
Successful exploitation results in complete takeover of the Oracle Agile PLM instance, giving the attacker control over application data and functions.
Attack surface
Reachable over HTTP by a low-privileged authenticated attacker; no user interaction is required per the CVSS vector (AV:N/AC:L/PR:L/UI:N).
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2025-02-24 with a remediation due date of 2025-03-17, indicating active exploitation. EPSS 30-day probability is about 3.9 percent (89.8th percentile); no ransomware campaign use is recorded.
What to do
- Apply the Oracle Critical Patch Update (January 2024) fix for Agile PLM 9.3.6 or upgrade to a supported release.
- If patching is not possible, restrict network access to the Agile PLM Export component and follow CISA's required action to discontinue use if no mitigation exists.
- Enforce least privilege and review accounts with low-privileged access that can reach the Export functionality.
- Monitor and limit HTTP access to the Agile PLM application from untrusted networks.
Detection
- Review Agile PLM application and web server logs for unusual Export component requests, especially from low-privileged accounts.
- Look for signs of deserialization abuse such as unexpected Java object payloads or anomalous process behavior on the Agile PLM host.
- Correlate network traffic to the Agile PLM HTTP endpoint with post-exploitation activity like new accounts or data exfiltration.
- Track CISA KEV status and verify patched versions across all Agile PLM 9.3.6 deployments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-20953 to the Known Exploited Vulnerabilities catalog on 24 February 2025 as "Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 17 March 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.oracle.com/security-alerts/cpujan2024.html | Vendor Advisory |
| https://www.oracle.com/security-alerts/cpujan2024.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-20953 | US Government Resource |
| https://www.zerodayinitiative.com/advisories/ZDI-24-096/ | Third Party Advisory |
Track CVE-2024-20953 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-20953), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.