Vulnerabilities > CVE-2014-0372 - SQL Injection vulnerability in Oracle products

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
oracle
exploit available

Summary

Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, and 12.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to DM Others.

Exploit-Db

descriptionOracle Demantra 12.2.1 - SQL Injection Vulnerability. CVE-2014-0372. Webapps exploit for windows platform
fileexploits/windows/webapps/31993.txt
idEDB-ID:31993
last seen2016-02-03
modified2014-03-01
platformwindows
port8080
published2014-03-01
reporterPortcullis
sourcehttps://www.exploit-db.com/download/31993/
titleOracle Demantra 12.2.1 - SQL Injection Vulnerability
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/125487/oracledemantra-sql.txt
idPACKETSTORM:125487
last seen2016-12-05
published2014-03-02
reporterOliver Gruskovnjak
sourcehttps://packetstormsecurity.com/files/125487/Oracle-Demantra-12.2.1-SQL-Injection.html
titleOracle Demantra 12.2.1 SQL Injection