Vulnerability record · CVE-2013-5795 · published 15 January 2014
CVE-2013-5795: Oracle Demantra Demand Management unspecified confidentiality flaw
Oracle · Supply Chain Products Suite
CVE-2013-5795 is an unspecified vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite, affecting versions 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2 and 12.2.3. The record gives no detail on the underlying flaw, only that remote attackers can affect confidentiality via unknown vectors related to DM Others. Because the mechanism is undisclosed, defenders cannot reason about the exact weakness and must rely on the vendor patch.
Description
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, and 12.2.3 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityCVSS 2.0 rates it 5.0 MEDIUM with confidentiality-only impact and no authentication, but the flaw is unspecified, not in KEV, and has no confirmed exploitation despite a high EPSS score.
What it is
CVE-2013-5795 is an unspecified vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite, affecting versions 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2 and 12.2.3. The record gives no detail on the underlying flaw, only that remote attackers can affect confidentiality via unknown vectors related to DM Others. Because the mechanism is undisclosed, defenders cannot reason about the exact weakness and must rely on the vendor patch.
Impact
An unauthenticated remote attacker can read data the component exposes, with no integrity or availability impact per the CVSS vector. The scope of the exposed data is not stated in the record.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N/C:P/I:N/A:N indicates network reachability, low attack complexity and no authentication requirement. No user interaction is indicated, but the record does not describe the specific interface or endpoint involved.
Exploitation
Not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation. EPSS is high (0.59494, 99.08th percentile), suggesting elevated predicted likelihood, but this is a model estimate, not evidence of active exploitation.
What to do
- Apply the Oracle Critical Patch Update January 2014 fix referenced in the vendor advisory, or a later CPU, to all listed Demantra versions.
- If patching cannot be done immediately, restrict network access to the Demantra Demand Management component to trusted hosts and users.
- Confirm which of the listed versions (7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, 12.2.3) are deployed and track them for patch status.
- Monitor Oracle advisories for any follow-up detail on the DM Others vectors, since the initial description is unspecified.
Detection
- Review Demantra application and web server logs for anomalous unauthenticated requests to Demand Management endpoints.
- Baseline normal access patterns to the component and alert on new or unusual source IPs and request volumes.
- Correlate outbound data transfers from Demantra hosts with access logs to spot possible data exfiltration.
- Track Oracle CPU patch level on Demantra hosts and alert on systems still running the affected versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-5795 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-5795), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.