vendor:
Secure Backup
by:
Oracle
N/A
CVSS
N/A
Remote Code Execution
N/A
CWE
Product Name: Secure Backup
Affected Version From: 10.1.0.3
Affected Version To: 10.2.0.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Unix
2009
Oracle Secure Backup 10g Remote Code Execution
The Oracle January 2009 Critical Patch Update fixes a vulnerability which allows a remote preauthenticated attacker to execute arbitrary code in the context of the user running the web server of Oracle Secure Backup. In Windows environments, the vulnerability allows execution of arbitrary code as SYSTEM. In Unix and GNU/Linux environments, however, just as a normal user (oracle usually).
Mitigation:
Oracle has released a patch for this vulnerability.