CVE-2014-2399
Endeca Latitude 2.2.2 - Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attackers to affect integrity via unknown vectors related to Oracle Endeca Information Discovery (Formerly Latitude), a different vulnerability than CVE-2014-2400.
Vulnerabilidad no especificada en el componente Oracle Endeca Server en Oracle Fusion Middleware 2.2.2 permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con Oracle Endeca Information Discovery (Formerly Latitude), una vulnerabilidad diferente a CVE-2014-2400.
RedTeam Pentesting discovered a cross site request forgery vulnerability in Endeca Latitude version 2.2.2. Using this vulnerability, an attacker might be able to change several different settings of the Endeca Latitude instance or disable it entirely.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-03-13 CVE Reserved
- 2014-04-16 CVE Published
- 2014-06-27 First Exploit
- 2024-08-06 CVE Updated
- 2024-11-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/127222/Endeca-Latitude-2.2.2-Cross-Site-Request-Forgery.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2014/Jun/123 | Mailing List | |
http://www.securityfocus.com/archive/1/532556/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/66864 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/33897 | 2014-06-27 | |
http://www.exploit-db.com/exploits/33897 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.html | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 2.2.2 Search vendor "Oracle" for product "Fusion Middleware" and version "2.2.2" | - |
Affected
|