5.8
CVSSv2

CVE-2014-2880

Published: 17/04/2014 Updated: 17/10/2014
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 585
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle identity manager 11.1.2.1.0

Exploits

Unvalidated Redirects on Oracle Identity Manager ======================================================================= [ADVISORY INFORMATION] Title: Unvalidated Redirects on Oracle Identity Manager Discovery date: 10/12/2013 Release date: 03/04/2014 Vendor Homepage: wwworaclecom Version: Oracle Identity Manager 11g R2 SP1 (11121 ...