Aller au contenu

Fiche vulnérabilité

CVE-2024-20953 : faille exploitée oracle agile product lifecycle… (CVSS 8.8)

Description

Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Oui, inscrite au catalogue CISA KEV
Publication
17 févr. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • oracle agile product lifecycle management

Correctif et mesures

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Références

Rechercher une autre vulnérabilité dans la base CVE