102095vdb entry
http://osvdb.org/102095 CVE-2013-5880
Oracle Supply Chain Products Suite - Remote Security
Record summary
CVE-2013-5880 has a selected CVSS score of 5.0; EIP currently links 3 catalogued exploits.
Description
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 3
Proofs of concept
3Catalogued exploits
ExploitDBOracle Supply Chain Products Suite - Remote SecurityExploitDB exploitby OracleNot analyzed1 file
MetasploitOracle Demantra Database Credentials LeakMetasploit auxiliary PoCby Oliver GruskovnjakNot analyzed1 file
MetasploitOracle Demantra Arbitrary File Retrieval with Authentication BypassMetasploit auxiliary PoCby Oliver GruskovnjakNot analyzed1 file
References
756474Third-party advisory
http://secunia.com/advisories/56474 oracle.comConfirmation
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html 64758vdb entry
http://www.securityfocus.com/bid/64758 64836vdb entry
http://www.securityfocus.com/bid/64836 1029620vdb entry
http://www.securitytracker.com/id/1029620 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-5880