Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-2399Oracle Fusion Middleware vulnerability

4 documents4 sources
Severity
4.3MEDIUMNVD
EPSS
26.7%
top 3.65%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 16
Latest updateMay 14

Description

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-387x-jwqw-43f3: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 22022-05-14
CVEList
CVE-2014-2399: Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 22014-04-16

💥Exploits & PoCs

1
Exploit-DB
Endeca Latitude 2.2.2 - Cross-Site Request Forgery2014-06-27
CVE-2014-2399 — Oracle Fusion Middleware vulnerability | cvebase