CVE-2014-2880
Last modified
CVE-2014-2880 is a vulnerability of currently unknown severity. Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.. EPSS estimates a 8.42% chance of exploitation in the next 30 days.
Description
Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backUrl parameter in a changepwd action to identity/faces/firstlogin.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Identity Manager | 11.1.2.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-2880?
How severe is CVE-2014-2880?
How do I fix CVE-2014-2880?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-2871PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relie…
- CVE-2014-2872PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow…
- CVE-2014-2873PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does …
- CVE-2014-2874PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow…
- CVE-2014-2875The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha …6.1
- CVE-2014-2879Multiple cross-site scripting (XSS) vulnerabilities in Dell …
- CVE-2014-2881Unspecified vulnerability in the Diffie-Hellman key agreemen…
- CVE-2014-2882Unspecified vulnerability in the management GUI in Citrix Ne…
- CVE-2014-2884The ProcessVolumeDeviceControlIrp function in Ntdriver.c in …
- CVE-2014-2885Multiple integer overflows in TrueCrypt 7.1a allow local use…
- CVE-2014-2886GKSu 2.0.2, when sudo-mode is not enabled, uses " (double qu…
- CVE-2014-2887Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2014-2880?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
