Advisory: Oracle Forms 10g Unauthenticated Remote Code Execution (CVE-2014-4278)
netspi.com | vulnerability | CVE-2014-4278 | #rce | #web-security | #input-validation | #oracle | #cve-2014-4278 | #oracle-forms
Summary
Oracle Forms 10g fails to validate the ifip parameter passed to ListenerServlet, letting unauthenticated attackers execute arbitrary commands; E-Business Suite 12.0.6-12.2.4 is also affected.
- CVE
- CVE-2014-4278
- Published
- Collected
Skip to content