← Vulnerability feed

Vulnerability record · CVE-2013-5880 · published 15 January 2014

CVE-2013-5880: Oracle Demantra Demand Management unspecified confidentiality flaw

Oracle · Supply Chain Products Suite

CVE-2013-5880 is an unspecified vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite 12.2.0, 12.2.1 and 12.2.2. It allows remote attackers to affect confidentiality via unknown vectors related to DM Others, and the record gives no detail on the underlying weakness. Because the flaw is undocumented, defenders cannot reason about the exact mechanism and must rely on the vendor patch.

5.0 CVSS 2.0 Medium EPSS 60% · top 0.9%
5.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: low.

medium priorityThe flaw is remotely reachable without authentication and has a very high EPSS score, but it is only a partial confidentiality impact, has no confirmed exploitation, and the affected product is a niche supply chain module.

What it is

CVE-2013-5880 is an unspecified vulnerability in the Oracle Demantra Demand Management component of Oracle Supply Chain Products Suite 12.2.0, 12.2.1 and 12.2.2. It allows remote attackers to affect confidentiality via unknown vectors related to DM Others, and the record gives no detail on the underlying weakness. Because the flaw is undocumented, defenders cannot reason about the exact mechanism and must rely on the vendor patch.

Impact

An attacker can read data the application would otherwise protect, affecting confidentiality only. No integrity or availability impact is described in the CVSS vector.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:P/I:N/A:N indicates the flaw is reachable over the network with no authentication and no user interaction. The specific interface or endpoint within DM Others is not described.

Exploitation

The record is not listed in CISA KEV and no reference carries an exploit tag, so there is no confirmed in-the-wild exploitation. EPSS is high (0.59558, 99th percentile), suggesting elevated likelihood of attempted exploitation, but this is a model estimate, not evidence of active attacks.

What to do

  • Apply the Oracle Critical Patch Update for January 2014, which addresses this issue, to Demantra Demand Management 12.2.0, 12.2.1 and 12.2.2.
  • If patching cannot be done immediately, restrict network access to the Demantra Demand Management component to trusted hosts and users.
  • Place the application behind authentication-aware proxies or VPN access so unauthenticated internet clients cannot reach it.
  • Monitor Oracle's advisory and successor CPU notices for any updated guidance or revised affected versions.
  • Review database and application logs for unexpected read activity against Demantra data.

Detection

  • Review web and application logs for anomalous or unexpected requests to Demantra Demand Management endpoints from unauthenticated or unfamiliar sources.
  • Baseline normal query and data-access patterns for Demantra users and alert on large or unusual reads of demand management data.
  • Monitor network traffic to the Demantra service for scanning or probing consistent with attempts to reach the DM Others vectors.
  • Track EPSS and KEV status for this CVE and escalate monitoring if exploitation evidence appears.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-5880 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2026-21940Oracle supply chain products suite information exposure vulnerabilityVulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: User and User Group). The supported version that is affected is 9.3.…EPSS 0.40%7.5CVE-2015-2663Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, and 6.3.0 through 6.3.7 a…EPSS 1.8%7.5CVE-2012-0549Oracle AutoVue Office Desktop API flaw allows remote compromiseCVE-2012-0549 is an unspecified vulnerability in the Oracle AutoVue Office component of Oracle Supply Chain Products Suite 20.1.1, tied to the Deskto…EPSS 59%analysed6.8CVE-2015-0435Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.…EPSS 1.3%6.8CVE-2014-6533Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1 and 6.2 allows remote attackers…EPSS 1.4%6.5CVE-2015-1793OpenSSL X.509 Basic Constraints flaw allows CA role spoofingOpenSSL 1.0.1n, 1.0.1o, 1.0.2b and 1.0.2c mishandle X.509 Basic Constraints cA values while identifying alternative certificate chains in X509_verify…EPSS 62%analysed6.5CVE-2015-2570Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Demand Planning component in Oracle Supply Chain Products Suite 11.5.10, 12.0, 12.1, and 12.2 allows remote a…EPSS 2.4%5.5CVE-2014-4229Oracle supply chain products suite vulnerabilityUnspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, and …EPSS 1.3%

Source: NIST National Vulnerability Database (record CVE-2013-5880), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.