packetstormsecurity.com
http://packetstormsecurity.com/files/125992/Oracle-Identity-Manager-11g-R2-SP1-Unvalidated-Redirect.html CVE-2014-2880
Oracle Identity Manager 11g R2 SP1 (11.1.2.1.0) - Unvalidated Redirects
Record summary
CVE-2014-2880 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.
Description
Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOracle Identity Manager 11g R2 SP1 (11.1.2.1.0) - Unvalidated RedirectsExploitDB exploitby Giuseppe D'AmoreNot analyzed1 file
References
632670exploit
http://www.exploit-db.com/exploits/32670 oracle.comConfirmation
http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html 105384vdb entry
http://www.osvdb.org/105384 66615vdb entry
http://www.securityfocus.com/bid/66615 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-2880