← Vulnerability feed

Vulnerability record · CVE-2014-2424 · published 16 April 2014

CVE-2014-2424: Oracle Event Processing FileUploadServlet arbitrary file upload

Oracle · Fusion Middleware

Oracle Fusion Middleware 11.1.1.7.0 contains an unspecified vulnerability in the Oracle Event Processing component, with public references pointing to an arbitrary file upload issue in FileUploadServlet. The flaw allows a remote authenticated user to affect integrity, and the public exploit code raises the risk of unauthorized file placement on the server.

4.0 CVSS 2.0 Medium EPSS 47% · top 1.2%
4.0CVSS 2.0 base score
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related to CEP system.

AV:N/AC:L/Au:S/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityPublic exploit code exists and EPSS is high, but exploitation requires authentication and the impact is limited to integrity, making it a high priority for exposed and unpatched systems.

What it is

Oracle Fusion Middleware 11.1.1.7.0 contains an unspecified vulnerability in the Oracle Event Processing component, with public references pointing to an arbitrary file upload issue in FileUploadServlet. The flaw allows a remote authenticated user to affect integrity, and the public exploit code raises the risk of unauthorized file placement on the server.

Impact

An attacker with valid credentials can upload arbitrary files to the Oracle Event Processing server, potentially overwriting or planting content that affects application integrity. Depending on server configuration, this could be leveraged for further compromise, though the record does not confirm code execution.

Attack surface

The vulnerability is reachable over the network via the Oracle Event Processing FileUploadServlet, requiring authentication as indicated by the CVSS vector (Au:S). No user interaction is required.

Exploitation

Public exploit code is available on Exploit-DB and Packet Storm, but the CVE is not listed in CISA KEV and no ransomware associations are documented. EPSS indicates a high probability of exploitation activity (0.47425, 98.8th percentile).

What to do

  • Apply the Oracle Critical Patch Update for April 2014 or the latest available Oracle Fusion Middleware patch addressing CVE-2014-2424.
  • Restrict network access to the Oracle Event Processing FileUploadServlet to trusted users and networks.
  • Enforce strong authentication and least-privilege accounts for Oracle Event Processing to limit the impact of authenticated exploitation.
  • Monitor and validate uploaded files, and disable or remove the FileUploadServlet if it is not required.

Detection

  • Monitor HTTP requests to the FileUploadServlet endpoint for unexpected or suspicious file uploads.
  • Alert on file creation or modification events in Oracle Event Processing upload directories.
  • Review authentication logs for unusual or unauthorized access to the Oracle Event Processing component.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-2424 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1710Oracle Fusion Middleware WebCenter Forms Recognition unspecified flawCVE-2012-1710 is an unspecified vulnerability in the Oracle WebCenter Forms Recognition component of Oracle Fusion Middleware 10.1.3.5, reachable thr…KEVEPSS 7.8%analysed9.1CVE-2012-3152Oracle Fusion Middleware Reports Developer arbitrary file read and uploadOracle Fusion Middleware's Reports Developer component (Report Server) contains an unspecified flaw that lets remote attackers affect confidentiality…KEVEPSS 99%analysed4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed10.0CVE-2013-2380Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware R27.7.4 and earlier and R28.2.6 and earlier allows remote attac…EPSS 2.1%10.0CVE-2012-3135Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.3 and before, and 27.7.2 and earlier, allows remote attack…EPSS 3.8%10.0CVE-2010-3510Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remo…EPSS 2.7%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.4CVE-2010-3599Oracle fusion middleware vulnerabilityUnspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affec…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2014-2424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.