Target Industry

Indiscriminate, opportunistic targeting.

Overview

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include two critical security flaws affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM). This decision is based on credible evidence of active exploitation in the wild. The inclusion of these vulnerabilities underscores the urgent need for organisations utilising these products to prioritise immediate mitigation efforts. 

CVE-2017-3066 (CVSS score: 9.8) - Is a critical security vulnerability with a CVSS score of 9.8, affecting Adobe ColdFusion through the Apache BlazeDS library. This deserialisation flaw allows attackers to execute arbitrary code by sending specially crafted serialised data to the server 

CVE-2024-20953 (CVSS score: 8.8) - Is a significant security vulnerability with a CVSS score of 8.8, impacting Oracle Agile Product Lifecycle Management (PLM). This deserialisation vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system. 

Impact

CVE-2024-20953 

This is a critical deserialisation vulnerability in Oracle Agile PLM, with a CVSS score of 8.8, allowing arbitrary code execution. Exploitable remotely without privileges or user interaction, it severely impacts confidentiality, integrity, and availability. Attackers can send crafted serialised data to compromise the system, leading to unauthorised access, data manipulation, and disruption.  

CVE-2017-3066  

If exploited, this vulnerability can lead to a full compromise of the Oracle Agile PLM system, allowing the attacker to control its confidentiality, integrity, and availability. They could access sensitive data, modify or delete information, and disrupt normal operations. Given that PLM systems often contain critical product and supply chain data, this could severely impact an organisation’s product development, manufacturing processes, and overall business operations. 

Vulnerability Detection

Adobe has released security updates to address this vulnerability, as indicated by the patch details provided by Adobe. 

Oracle released a security update to address this vulnerability on 16th January 2024, as part of their Critical Patch Update. 

Exploitation

CVE-2024-20953 is highly exploitable due to its low requirement for privileges and the ease of network access via HTTP. An attacker could potentially use a proof-of-concept (PoC) exploit available on GitHub to gain unauthorised access and control. Although there is currently no evidence of active exploitation in the wild, the availability of the PoC increases the risk of imminent attacks. Attackers leveraging this vulnerability could execute arbitrary code, manipulate data, and disrupt services, leading to significant operational and financial damage. 

CVE-2017-3066 is highly exploitable due to its remote attack vector, lack of required privileges, and no need for user interaction. A PoC exploit is available on exploit-db.com, highlighting the ease with which attackers could potentially exploit this flaw. Although there is no evidence of active exploitation at the moment, the availability of the PoC increases the likelihood of imminent attacks. Exploitation could result in unauthorised code execution, data manipulation, and disruption of services, leading to severe operational and security consequences. 

Containment, Mitigations & Remediation

A patch has been released to remediate both vulnerabilities. It is strongly recommended that users apply this update immediately to ensure their systems are protected against potential exploitation.  

Threat Landscape

Adobe ColdFusion is a rapid web application development platform used for building dynamic websites and internet applications. It features an easy-to-use scripting language (CFML) and integrates well with various databases and web technologies. Widely adopted by enterprises and government organisations, ColdFusion streamlines development and manages complex web infrastructures efficiently. However, its popularity also makes it a target for security vulnerabilities, highlighting the need for regular updates 

Oracle Agile PLM is a comprehensive product lifecycle management solution used to manage product innovation, development, and compliance processes. It supports collaboration across various departments, including engineering, manufacturing, and supply chain management. Widely utilised by large enterprises, Agile PLM helps streamline product data, improve time-to-market, and ensure regulatory compliance. Due to its extensive use in managing critical product and supply chain information, maintaining its security is paramount to protect sensitive business operations and data. 

Threat Group

No attribution to specific threat actors or groups has been identified at the time of writing. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content