Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: Mar 17, 2025

CVE-2024-20953

High
EPSS 69.0%CISA KEV
Oracle/Agile Product Lifecycle Management (PLM)

Description

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.

EPSS — Exploit Probability

69.0%

Higher than 98.6% of all CVEs

Required Action

https://www.oracle.com/security-alerts/cpujan2024.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-20953

Risk Assessment

HIGH
In CISA KEV
High EPSS

Details

Severity
High
EPSS
69.0%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

Feb 24, 2025

Added to KEV

Feb 24, 2025

Remediation Due

Mar 17, 2025

Affected Product

Oracle

Agile Product Lifecycle Management (PLM)

View all Oracle CVEs