← Back to browse · API

CVE-2024-20953

Severity
HIGH
CVSS
8.8
EPSS
0.03405
Risk score
61.39
CISA KEV
Yes
PoC
No
Published
2024-02-17
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2024-18667, GHSA-F4JC-JXP8-5PV7
Products
Oracle Corporation:Agile PLM Framework 9.3.6, Oracle:Agile Product Lifecycle Management (PLM)
Sources
euvd EUVD-2024-18667
cisa.gov CVE-2024-20953

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

References