Oracle Event Processing FileUploadServlet Directory Traversal (CVE-2014-2424)

A code execution vulnerability has been reported in Oracle Event Processing. The vulnerability is due to a directory traversal within the FileUploadServlet servlet. A remote unauthenticated attacker can exploit this vulnerability by sending a maliciously crafted HTTP request.

Leave a Reply