Record summary

CVE-2014-2880 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.

Description

Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOracle Identity Manager 11g R2 SP1 (11.1.2.1.0) - Unvalidated RedirectsExploitDB exploitby Giuseppe D'AmoreNot analyzed1 file
ExploitDB

PoC details

References

6