Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-0372. PoCs published by Portcullis.
AI-analyzed exploit summary This exploit demonstrates SQL injection in Oracle Demantra's editExecDefinition.jsp and saveProgramGroups.jsp endpoints. The PoC shows how malformed input can terminate SQL strings improperly, leading to potential data extraction or manipulation.
Description
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to DM Others.
Exploits (1)
This exploit demonstrates SQL injection in Oracle Demantra's editExecDefinition.jsp and saveProgramGroups.jsp endpoints. The PoC shows how malformed input can terminate SQL strings improperly, leading to potential data extraction or manipulation.