← Vulnerability feed

Vulnerability record · CVE-2013-5877 · published 15 January 2014

CVE-2013-5877: Oracle Demantra Demand Management unspecified confidentiality flaw

Oracle · Supply Chain Products Suite

CVE-2013-5877 is an unspecified vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite versions 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0 and 12.2.1. Oracle's advisory and NVD provide no technical detail beyond 'DM Others', so the exact mechanism is unknown, but the flaw permits remote attackers to affect confidentiality. It matters because the affected component is reachable over the network without authentication, and the record gives no workaround beyond Oracle's January 2014 Critical Patch Update.

5.0 CVSS 2.0 Medium EPSS 55% · top 1.0%
5.0CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0, and 12.2.1 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS 2.0 base score is 5.0 (medium) with only partial confidentiality impact, but the flaw is remotely reachable without authentication and EPSS is high, so it warrants prompt patching rather than emergency action.

What it is

CVE-2013-5877 is an unspecified vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite versions 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0 and 12.2.1. Oracle's advisory and NVD provide no technical detail beyond 'DM Others', so the exact mechanism is unknown, but the flaw permits remote attackers to affect confidentiality. It matters because the affected component is reachable over the network without authentication, and the record gives no workaround beyond Oracle's January 2014 Critical Patch Update.

Impact

An attacker can read data the application exposes, limited to partial confidentiality impact; there is no integrity or availability impact in the CVSS vector. The specific data exposed is not described in the record.

Attack surface

Network-reachable (AV:N) with low attack complexity and no authentication required (AC:L/Au:N), per the CVSS 2.0 vector. No user interaction is indicated, and the record does not identify the exact endpoint or protocol.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, so there is no confirmed public exploitation. EPSS is high (0.54975, 98.978th percentile), indicating elevated predicted likelihood of exploitation activity, though the score is a model estimate rather than evidence of a working exploit.

What to do

  • Apply the Oracle January 2014 Critical Patch Update (cpujan2014-1972949) or a later CPU that includes the fix for Demantra Demand Management.
  • If patching cannot be done immediately, restrict network access to the Demantra Demand Management component to trusted hosts and users.
  • Verify which listed versions (7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0, 12.2.1) are deployed and prioritize internet-facing or broadly reachable instances.
  • Monitor Oracle's advisory and successor CPUs for any updated guidance, since the original description lacks technical detail.

Detection

  • Review Demantra Demand Management access logs for anomalous or unexpected read activity from unauthenticated or unfamiliar source addresses.
  • Alert on scanning or enumeration attempts against the Demantra web endpoints, since the flaw is remotely reachable without credentials.
  • Correlate outbound data volume from Demantra hosts against normal baselines to catch bulk data retrieval.
  • Track Oracle CPU compliance for the affected Supply Chain Products Suite instances and flag unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-5877 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-21940Oracle supply chain products suite information exposure vulnerabilityVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.…EPSS 0.40%7.5CVE-2015-2663Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 a…EPSS 1.8%7.5CVE-2012-0549Oracle AutoVue Office Desktop API flaw allows remote compromiseCVE-2012-0549 is an unspecified vulnerability in the Oracle AutoVue Office component of Oracle Supply Chain Products Suite 20.1.1, tied to the Deskto…EPSS 59%analysed6.8CVE-2015-0435Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.…EPSS 1.3%6.8CVE-2014-6533Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1 and 6.2 allows remote attackers…EPSS 1.4%6.5CVE-2015-1793OpenSSL X.509 Basic Constraints flaw allows CA role spoofingOpenSSL 1.0.1n, 1.0.1o, 1.0.2b and 1.0.2c mishandle X.509 Basic Constraints cA values while identifying alternative certificate chains in X509_verify…EPSS 62%analysed6.5CVE-2015-2570Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Demand Planning component in Oracle Supply Chain Products Suite 11.5.10, 12.0, 12.1, and 12.2 allows remote a…EPSS 2.4%5.5CVE-2014-4229Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2013-5877), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.