vendor:
GoldenGate
by:
Silent Signal
N/A
CVSS
N/A
Remote Code Execution
78
CWE
Product Name: GoldenGate
Affected Version From: 12.1.2.0.0
Affected Version To: 12.1.2.0.0
Patch Exists: YES
Related CWE: CVE-2017-10269
CPE: a:oracle:goldengate
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows
2017
GOLDENSHOWER – Oracle GoldenGate unauthenticated RCE by Silent Signal
GOLDENSHOWER is an unauthenticated Remote Code Execution (RCE) vulnerability in Oracle GoldenGate. It allows an attacker to execute arbitrary commands on the target system without authentication. The vulnerability is caused by the lack of authentication in the Oracle GoldenGate Manager service, which allows an attacker to send specially crafted requests to the service and execute arbitrary commands on the target system. The vulnerability affects Oracle GoldenGate versions 12.1.2.0.0 and earlier.
Mitigation:
The vendor has released a patch to address the vulnerability. Users should upgrade to the latest version of Oracle GoldenGate.