CVE-2013-3763

Oracle Endeca Server - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2013-3763. PoCs published by Metasploit, including Metasploit module exploits/windows/http/oracle_endeca_exec.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Oracle Endeca Server 7.4.0 via the createDataStore method in the controlSoapBinding web service. It uses PowerShell to execute a payload, targeting Windows systems.

Description

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3764.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/27877

This Metasploit module exploits a command injection vulnerability in Oracle Endeca Server 7.4.0 via the createDataStore method in the controlSoapBinding web service. It uses PowerShell to execute a payload, targeting Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle Endeca Server 7.4.0
No auth needed
Prerequisites: Network access to the target server · SOAP service exposed on port 7770
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/oracle_endeca_exec.rb

This Metasploit module exploits a command injection vulnerability in Oracle Endeca Server 7.4.0 via the createDataStore method in the controlSoapBinding web service. It uses SOAP requests to inject and execute PowerShell commands, achieving remote code execution on Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Oracle Endeca Server 7.4.0
No auth needed
Prerequisites: Network access to the Oracle Endeca Server control web service (port 7770 by default) · Target running Oracle Endeca Server 7.4.0 on Windows
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-13-190/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1028801

Scores

EPSS 0.7218
EPSS Percentile 98.8%

Details

Status published
Products (2)
oracle/fusion_middleware 7.4.0
oracle/fusion_middleware 7.5.1.1
Published Jul 17, 2013
Tracked Since Feb 18, 2026