peter bassill · operator
$ cve CVE-2014-2880 JSON

CVE-2014-2880 EXPLOIT

5.8
MEDIUM · CVSS 2.0 · EPSS 8.5% (pctl 95)

Patch early

A public exploit exists.

Description

Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.

Scoring

CVSS5.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS8.49% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2014-04-17
Last modified2026-06-17

Affected (1)

VendorProduct
oracleidentity manager

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD