Adobe and Oracle Known Exploited Vulnerabilities - 20250225001¶
Overview¶
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilites Catalog, based on evidence of active exploitation. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
What is vulnerable?¶
Product(s) Affected | Version(s) | CVE | CVSS | Severity |
---|---|---|---|---|
Adobe ColdFusion | - 2016 Update 3 and earlier - ColdFusion 11 update 11 and earlier - ColdFusion 10 Update 22 and earlier |
CVE-2017-3066 | 9.8 | Critical |
Oracle Agile Product Lifecycle Management (PLM) | - 9.3.6 | CVE-2024-20953 | 8.8 | High |
What has been observed?¶
CISA added these vulnerabilities to their Known Exploited Vulnerabilities catalog. There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.
Recommendation¶
The WA SOC recommends administrators apply the solutions as per both vendors instructions to all affected devices within expected timeframe of 48 hours... as shown in Patch Management: