CVE-2014-2457: Medium severity Oracle Supply Chain Products Suite vulnerability
Unspecified vulnerability in the Oracle Agile Product Lifecycle component in Oracle Supply Chain Products Suite 6.0 and 6.1.0 allows remote attackers to affect integrity via unknown vectors related to Install.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to the Oracle Supply Chain Products Suite 6.0 and 6.1.0 “Install” functionality/component (Oracle Agile Product Lifecycle) so remote attackers cannot reach it.
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2457?
The severity of CVE-2014-2457 is not explicitly rated but is related to integrity concerns in the affected Oracle Supply Chain Products.
How do I fix CVE-2014-2457?
To fix CVE-2014-2457, apply the latest patches provided by Oracle for the affected versions of the Supply Chain Products Suite.
What versions are affected by CVE-2014-2457?
CVE-2014-2457 affects Oracle Supply Chain Products Suite versions 6.0.0 and 6.1.0.
Can CVE-2014-2457 be exploited remotely?
Yes, CVE-2014-2457 can be exploited remotely by attackers to affect the integrity of the Oracle Agile Product Lifecycle component.
What type of vulnerability is CVE-2014-2457 classified as?
CVE-2014-2457 is classified as an unspecified vulnerability within the Oracle Agile Product Lifecycle component.