PT-2014-4688 · Oracle · Oracle Event Processing+1

Publicado

2014-04-16

·

Atualizado

2014-07-24

·

CVE-2014-2424

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Fusion Middleware versions 11.1.1.7.0
Description The issue affects the integrity of the system, allowing remote authenticated users to exploit it via vectors related to the CEP system in the Oracle Event Processing component. This can potentially lead to remote code execution.
Recommendations For Oracle Fusion Middleware version 11.1.1.7.0, consider restricting access to the FileUploadServlet to minimize the risk of exploitation until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2014-2424
ZDI-14-106

Produtos afetados

Oracle Event Processing
Oracle Fusion Middleware