Oracle Agile Product Lifecycle Management (PLM) 9.3.6.x < 9.3.6.26

high Nessus Plugin ID 216910

Synopsis

The remote host is affected by multiple vulnerabilities.

Description

The version of Oracle Agile Product Lifecycle Management (PLM) on the remote host is 9.3.6.x prior to 9.3.6.26. It is, therefore, affected by multiple vulnerabilities, including:

- Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Export). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. (CVE-2024-20953)
- The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. (CVE-2023-44487)
- An issue was discovered htmlcleaner thru = 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies. (CVE-2023-34624)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Oracle Agile Product Lifecycle Management (PLM) version 9.3.6.26 or later

See Also

http://www.nessus.org/u?05d9c42d

Plugin Details

Severity: High

ID: 216910

File Name: oracle_agile_plm_9_3_6_26.nasl

Version: 1.3

Type: local

Agent: windows, macosx, unix

Family: Misc.

Published: 2/27/2025

Updated: 2/28/2025

Configuration: Enable thorough checks

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-20953

CVSS v3

Risk Factor: High

Base Score: 7.1

Temporal Score: 6.6

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS Score Source: CVE-2023-2976

Vulnerability Information

CPE: cpe:/a:oracle:agile_plm

Required KB Items: installed_sw/Oracle Agile Product Lifecycle Management (PLM)

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 1/16/2024

Vulnerability Publication Date: 1/16/2024

CISA Known Exploited Vulnerability Due Dates: 10/31/2023, 3/17/2025

Reference Information

CVE: CVE-2023-2976, CVE-2023-34624, CVE-2023-42794, CVE-2023-42795, CVE-2023-44487, CVE-2023-45648, CVE-2024-20953