CVE-2014-2399
published 2014-04-16CVE-2014-2399: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown…
PriorityP431medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
6.98%
93.4th percentile
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Endeca Server 2.2.2 Endeca Information Discovery (EDB-33897 / SBV-44062)
vuldb·2026-05-11·CVSS 4.3
CVE-2014-2399 [MEDIUM] Oracle Endeca Server 2.2.2 Endeca Information Discovery (EDB-33897 / SBV-44062)
A vulnerability classified as problematic was found in Oracle Endeca Server 2.2.2. This affects an unknown part of the component Endeca Information Discovery Handler. The manipulation results in an unknown weakness.
This vulnerability is cataloged as CVE-2014-2399. The attack may be launched remotely. Furthermore, there is an exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-387x-jwqw-43f3: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2014-2399 [MEDIUM] GHSA-387x-jwqw-43f3: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.
GHSA
GHSA-j9c6-8ccv-jvv5: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2
ghsa_unreviewed·2022-05-14·CVSS 4.3
CVE-2014-2400 [MEDIUM] GHSA-j9c6-8ccv-jvv5: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2399.
No detection rules found.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/127222/Endeca-Latitude-2.2.2-Cross-Site-Request-Forgery.htmlhttp://seclists.org/fulldisclosure/2014/Jun/123http://www.exploit-db.com/exploits/33897http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/archive/1/532556/100/0/threadedhttp://www.securityfocus.com/bid/66864http://packetstormsecurity.com/files/127222/Endeca-Latitude-2.2.2-Cross-Site-Request-Forgery.htmlhttp://seclists.org/fulldisclosure/2014/Jun/123http://www.exploit-db.com/exploits/33897http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/archive/1/532556/100/0/threadedhttp://www.securityfocus.com/bid/66864
2014-04-16
Published