CVE-2014-4249
Oracle Business Intelligence Mobile App Designer UIXCacheResourceServlet Information Disclosure Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the BI Publisher component in Oracle Fusion Middleware 11.1.1.7 allows remote attackers to affect confidentiality via unknown vectors related to Mobile Service.
Vulnerabilidad no especificada en el componente BI Publisher en Oracle Fusion Middleware 11.1.1.7 permite a atacantes remotos afectar la confidencialidad a través de vectores desconocidos relacionados con Mobile Service.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Business Intelligence Mobile App Designer. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the UIXCacheResourceServlet servlet. The issue lies in the ability to download arbitrary files using a directory traversal vulnerability. A remote attacker can abuse this to disclose sensitive information that could result in remote code under the context of the process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-06-17 CVE Reserved
- 2014-07-17 CVE Published
- 2024-02-27 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2014/Dec/23 | Mailing List | |
http://secunia.com/advisories/59111 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/534161/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/68605 | Vdb Entry | |
http://www.vmware.com/security/advisories/VMSA-2014-0012.html | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/94550 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html | 2018-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 11.1.1.7.0 Search vendor "Oracle" for product "Fusion Middleware" and version "11.1.1.7.0" | - |
Affected
|