PT-2014-4688 · Oracle · Oracle Event Processing+1

Published

2014-04-16

·

Updated

2014-07-24

·

CVE-2014-2424

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Fusion Middleware versions 11.1.1.7.0
Description The issue affects the integrity of the system, allowing remote authenticated users to exploit it via vectors related to the CEP system in the Oracle Event Processing component. This can potentially lead to remote code execution.
Recommendations For Oracle Fusion Middleware version 11.1.1.7.0, consider restricting access to the FileUploadServlet to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-2424
ZDI-14-106

Affected Products

Oracle Event Processing
Oracle Fusion Middleware