CVE-2014-2404
published 2014-04-16CVE-2014-2404: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3, 11.1.1.3.0, 11.1.1.5.0, 11.1.1.7.0, 11.1.2.0.0…
PriorityP420medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
2.55%
83.4th percentile
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3, 11.1.1.3.0, 11.1.1.5.0, 11.1.1.7.0, 11.1.2.0.0, 11.1.2.1.0, and 11.1.2.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to WebGate.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Access Manager up to 11.1.2.2.0 WebGate information disclosure (SBV-44070 / BID-66862)
vuldb·2026-05-11·CVSS 4.0
CVE-2014-2404 [MEDIUM] Oracle Access Manager up to 11.1.2.2.0 WebGate information disclosure (SBV-44070 / BID-66862)
A vulnerability, which was classified as problematic, was found in Oracle Access Manager up to 11.1.2.2.0. This issue affects some unknown processing of the component WebGate. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2014-2404. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
GHSA-58j4-pf6x-qc98: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10
ghsa_unreviewed·2022-05-17
CVE-2014-2404 [MEDIUM] GHSA-58j4-pf6x-qc98: Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3, 11.1.1.3.0, 11.1.1.5.0, 11.1.1.7.0, 11.1.2.0.0, 11.1.2.1.0, and 11.1.2.2.0 allows remote authenticated users to affect confidentiality via unknown vectors related to WebGate.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/127047/Oracle-Access-Manager-Information-Disclosure.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66862http://packetstormsecurity.com/files/127047/Oracle-Access-Manager-Information-Disclosure.htmlhttp://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/bid/66862
2014-04-16
Published