This is a critical deserialization vulnerability in Oracle Agile PLM that allows complete system takeover via HTTP network access with low privileges. The vulnerability is actively exploited in the wild and listed in CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2024-02-17
Added to CISA KEV: 2025-02-24 373 DAYS BETWEEN CVE AND KEV
CVE-2024-20953 is a high-severity remote code execution (RCE) vulnerability affecting the Oracle Agile Product Lifecycle Management (PLM) product [4] [1].
Threat Intelligence Report CVE-2024-20953 is a critical deserialization vulnerability in Oracle Agile Product Lifecycle Management (PLM) that allows attackers to execute arbitrary code by improperly deserializing untrusted data. The inclusion of this vulnerability in CISAβs KEV Catalog underscores tβ¦
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. ... CVE-2024-20953 Detail. Description. Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export).Easily exploitable vulnerability allows low prβ¦
A high-severity deserialization vulnerability in Oracle Agile PLM allows low-privileged attackers to compromise the system via HTTP.
CVE-2024-20953 is a remote code execution vulnerability in Oracle Agile PLM. Learn about its impact, affected versions, and mitigation methods. ... This vulnerability enables a low-privileged attacker with network access via HTTP to achieve complete compromise of the Oracle Agile PLM system, ...
Oracle Critical Patch Update Advisory - January 2024. Description. A Critical Patch Update is a collection of patches for multiple security vulnerabilities.