CVE-2014-2424 EXPLOIT
4.0
MEDIUM · CVSS 2.0 · EPSS 47.4% (pctl 99)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.
Scoring
| CVSS | 4.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
| EPSS | 47.43% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-04-16 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| oracle | fusion middleware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Oracle Event Processing FileUploadServlet - Arbitrary File Upload (Metasploit) | 2014-07-07 |
References
- http://packetstormsecurity.com/files/127365/Oracle-Event-Processing-FileUploadServlet-Arbitrary-File-Upload.html
- http://www.exploit-db.com/exploits/33989
- http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
- http://www.osvdb.org/105844
- http://www.securityfocus.com/bid/66871
- http://packetstormsecurity.com/files/127365/Oracle-Event-Processing-FileUploadServlet-Arbitrary-File-Upload.html
- http://www.exploit-db.com/exploits/33989
- http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html
- http://www.osvdb.org/105844
- http://www.securityfocus.com/bid/66871
→ the Explorer · watch your stack · NVD