Skip to content

Adobe and Oracle Known Exploited Vulnerabilities - 20250225001

Overview

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilites Catalog, based on evidence of active exploitation. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

What is vulnerable?

Product(s) Affected Version(s) CVE CVSS Severity
Adobe ColdFusion - 2016 Update 3 and earlier
- ColdFusion 11 update 11 and earlier
- ColdFusion 10 Update 22 and earlier
CVE-2017-3066 9.8 Critical
Oracle Agile Product Lifecycle Management (PLM) - 9.3.6 CVE-2024-20953 8.8 High

What has been observed?

CISA added these vulnerabilities to their Known Exploited Vulnerabilities catalog. There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

Recommendation

The WA SOC recommends administrators apply the solutions as per both vendors instructions to all affected devices within expected timeframe of 48 hours... as shown in Patch Management:

References