Target Industry
Indiscriminate, opportunistic targeting.
Overview
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) catalog to include two critical security flaws affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM). This decision is based on credible evidence of active exploitation in the wild. The inclusion of these vulnerabilities underscores the urgent need for organisations utilising these products to prioritise immediate mitigation efforts.
CVE-2017-3066 (CVSS score: 9.8) - Is a critical security vulnerability with a CVSS score of 9.8, affecting Adobe ColdFusion through the Apache BlazeDS library. This deserialisation flaw allows attackers to execute arbitrary code by sending specially crafted serialised data to the server
CVE-2024-20953 (CVSS score: 8.8) - Is a significant security vulnerability with a CVSS score of 8.8, impacting Oracle Agile Product Lifecycle Management (PLM). This deserialisation vulnerability allows a low-privileged attacker with network access via HTTP to compromise the system.
Impact
CVE-2024-20953
This is a critical deserialisation vulnerability in Oracle Agile PLM, with a CVSS score of 8.8, allowing arbitrary code execution. Exploitable remotely without privileges or user interaction, it severely impacts confidentiality, integrity, and availability. Attackers can send crafted serialised data to compromise the system, leading to unauthorised access, data manipulation, and disruption.
CVE-2017-3066
If exploited, this vulnerability can lead to a full compromise of the Oracle Agile PLM system, allowing the attacker to control its confidentiality, integrity, and availability. They could access sensitive data, modify or delete information, and disrupt normal operations. Given that PLM systems often contain critical product and supply chain data, this could severely impact an organisation’s product development, manufacturing processes, and overall business operations.
Vulnerability Detection
Adobe has released security updates to address this vulnerability, as indicated by the patch details provided by Adobe.
Oracle released a security update to address this vulnerability on 16th January 2024, as part of their Critical Patch Update.
Exploitation
CVE-2024-20953 is highly exploitable due to its low requirement for privileges and the ease of network access via HTTP. An attacker could potentially use a proof-of-concept (PoC) exploit available on GitHub to gain unauthorised access and control. Although there is currently no evidence of active exploitation in the wild, the availability of the PoC increases the risk of imminent attacks. Attackers leveraging this vulnerability could execute arbitrary code, manipulate data, and disrupt services, leading to significant operational and financial damage.
CVE-2017-3066 is highly exploitable due to its remote attack vector, lack of required privileges, and no need for user interaction. A PoC exploit is available on exploit-db.com, highlighting the ease with which attackers could potentially exploit this flaw. Although there is no evidence of active exploitation at the moment, the availability of the PoC increases the likelihood of imminent attacks. Exploitation could result in unauthorised code execution, data manipulation, and disruption of services, leading to severe operational and security consequences.
Containment, Mitigations & Remediation
A patch has been released to remediate both vulnerabilities. It is strongly recommended that users apply this update immediately to ensure their systems are protected against potential exploitation.
Threat Landscape
Adobe ColdFusion is a rapid web application development platform used for building dynamic websites and internet applications. It features an easy-to-use scripting language (CFML) and integrates well with various databases and web technologies. Widely adopted by enterprises and government organisations, ColdFusion streamlines development and manages complex web infrastructures efficiently. However, its popularity also makes it a target for security vulnerabilities, highlighting the need for regular updates
Oracle Agile PLM is a comprehensive product lifecycle management solution used to manage product innovation, development, and compliance processes. It supports collaboration across various departments, including engineering, manufacturing, and supply chain management. Widely utilised by large enterprises, Agile PLM helps streamline product data, improve time-to-market, and ensure regulatory compliance. Due to its extensive use in managing critical product and supply chain information, maintaining its security is paramount to protect sensitive business operations and data.
Threat Group
No attribution to specific threat actors or groups has been identified at the time of writing.












