vendor:
Secure Backup Administration Server
by:
Luca 'ikki' Carettoni
7.5
CVSS
HIGH
Authentication Bypass and Command Injection
287, 78
CWE
Product Name: Secure Backup Administration Server
Affected Version From: 10.3.0.1.0_win32_release
Affected Version To: 10.3.0.1.0_win32_release
Patch Exists: YES
Related CWE: CVE-2009-1977, CVE-2009-1978
CPE: a:oracle:secure_backup_administration_server:10.3.0.1.0_win32_release
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: MS Windows Professional XP SP3
2009
Oracle Secure Backup Administration Server authentication bypass, plus command injection vulnerability
In August 2009, ZDI discloses a few details regarding a couple of interesting vulnerabilities within Oracle Backup Admin server. Since I was quite interested in such flaws, I did a bit of research. This PoC exploits two separate vulnerabilities: a smart authentication bypass and a trivial command injection, resulting in arbitrary command execution.
Mitigation:
Ensure that the Oracle Secure Backup Administration Server is up to date with the latest security patches.