Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-0372Oracle Supply Chain Products Suite vulnerability

5 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
20.5%
top 4.44%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJan 15
Latest updateMay 14

Description

Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to DM Others.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 8.0 | Impact: 4.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-mp2c-hhj2-7xjx: Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 72022-05-14
CVEList
CVE-2014-0372: Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 72014-01-15

💥Exploits & PoCs

1
Exploit-DB
Oracle Demantra 12.2.1 - SQL Injection2014-03-01

💬Community

1
Bugzilla
CVE-2013-6468 Drools: Remote Java Code Execution in MVEL2014-01-09
CVE-2014-0372 — Oracle vulnerability | cvebase