Vulnerability record · CVE-2014-2424 · published 16 April 2014
CVE-2014-2424: Oracle Event Processing FileUploadServlet arbitrary file upload
Oracle · Fusion Middleware
Oracle Fusion Middleware 11.1.1.7.0 contains an unspecified vulnerability in the Oracle Event Processing component, with public references pointing to an arbitrary file upload issue in FileUploadServlet. The flaw allows a remote authenticated user to affect integrity, and the public exploit code raises the risk of unauthorized file placement on the server.
Description
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.
AV:N/AC:L/Au:S/C:N/I:P/A:N
Automated analysis
high priorityPublic exploit code exists and EPSS is high, but exploitation requires authentication and the impact is limited to integrity, making it a high priority for exposed and unpatched systems.
What it is
Oracle Fusion Middleware 11.1.1.7.0 contains an unspecified vulnerability in the Oracle Event Processing component, with public references pointing to an arbitrary file upload issue in FileUploadServlet. The flaw allows a remote authenticated user to affect integrity, and the public exploit code raises the risk of unauthorized file placement on the server.
Impact
An attacker with valid credentials can upload arbitrary files to the Oracle Event Processing server, potentially overwriting or planting content that affects application integrity. Depending on server configuration, this could be leveraged for further compromise, though the record does not confirm code execution.
Attack surface
The vulnerability is reachable over the network via the Oracle Event Processing FileUploadServlet, requiring authentication as indicated by the CVSS vector (Au:S). No user interaction is required.
Exploitation
Public exploit code is available on Exploit-DB and Packet Storm, but the CVE is not listed in CISA KEV and no ransomware associations are documented. EPSS indicates a high probability of exploitation activity (0.47425, 98.8th percentile).
What to do
- Apply the Oracle Critical Patch Update for April 2014 or the latest available Oracle Fusion Middleware patch addressing CVE-2014-2424.
- Restrict network access to the Oracle Event Processing FileUploadServlet to trusted users and networks.
- Enforce strong authentication and least-privilege accounts for Oracle Event Processing to limit the impact of authenticated exploitation.
- Monitor and validate uploaded files, and disable or remove the FileUploadServlet if it is not required.
Detection
- Monitor HTTP requests to the FileUploadServlet endpoint for unexpected or suspicious file uploads.
- Alert on file creation or modification events in Oracle Event Processing upload directories.
- Review authentication logs for unusual or unauthorized access to the Oracle Event Processing component.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2424 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.