PT-2024-1347 · Oracle · Oracle Agile Plm
Published
2024-01-16
·
Updated
2026-06-02
·
CVE-2024-20953
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Agile PLM version 9.3.6
Description
The issue is related to the deserialization of untrusted data in the Export component of Oracle Agile PLM, which can be exploited by a remote attacker to execute arbitrary code. This vulnerability is easily exploitable and can result in the takeover of Oracle Agile PLM. The vulnerability has been reported to be exploited in the wild.
Recommendations
For Oracle Agile PLM version 9.3.6, consider disabling the Export component until a patch is available. Restrict access to the Export component to minimize the risk of exploitation. Avoid using the Export component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Agile Plm