Oracle Event Processing CVE-2014-2424 Remote Code Execution Vulnerability
BID:66871
Info
Oracle Event Processing CVE-2014-2424 Remote Code Execution Vulnerability
| Bugtraq ID: | 66871 |
| Class: | Unknown |
| CVE: |
CVE-2014-2424 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2014 12:00AM |
| Updated: | Jul 08 2014 12:26AM |
| Credit: | Oracle |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle Event Processing CVE-2014-2424 Remote Code Execution Vulnerability
Oracle Event Processing is prone to a remote code execution vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'CEP system' sub component is affected.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
This vulnerability affects the following supported versions:
11.1.1.7.0
Oracle Event Processing is prone to a remote code execution vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'CEP system' sub component is affected.
Successfully exploiting this issue allows attackers to execute arbitrary code in the context of the affected application.
This vulnerability affects the following supported versions:
11.1.1.7.0
Exploit / POC
Oracle Event Processing CVE-2014-2424 Remote Code Execution Vulnerability
The following exploit code is available.
The following exploit code is available.
Solution / Fix
Oracle Event Processing CVE-2014-2424 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle Event Processing CVE-2014-2424 Remote Code Execution Vulnerability
References:
References: