Oracle Event Processing CVE-2014-2424 Unspecified Vulnerability (April 2014 CPU)

medium Nessus Plugin ID 74151
New! Vulnerability Priority Rating (VPR)

Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it is different from CVSS.

VPR Score: 4

Synopsis

The remote host is affected by an unspecified remote directory traversal vulnerability.

Description

The remote host is missing a vendor supplied security update that fixes an unspecified security vulnerability that allows authenticated attackers to create files outside of the intended path by utilizing a directory traversal string.

Solution

Apply the Oracle April 2014 Critical Patch Update.

See Also

http://www.nessus.org/u?ef1fc2a6

Plugin Details

Severity: Medium

ID: 74151

File Name: oracle_cep_cve_2014_2424.nbin

Version: 1.111

Type: local

Family: Misc.

Published: 5/20/2014

Updated: 4/14/2021

Dependencies: oracle_event_processing_installed.nbin

Risk Information

Risk Factor: Medium

VPR Score: 4

CVSS v2.0

Base Score: 4

Temporal Score: 3.3

Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Temporal Vector: E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:fusion_middleware

Required KB Items: Oracle/OEP/Installed

Exploit Available: true

Exploit Ease: Exploits are available

Exploitable With

Metasploit (Oracle Event Processing FileUploadServlet Arbitrary File Upload)

Reference Information

CVE: CVE-2014-2424

BID: 66871