vendor:
Oracle VM
by:
Nahuel Grisolia
N/A
CVSS
N/A
Injection
78
CWE
Product Name: Oracle VM
Affected Version From: Oracle Virtual Server release 2.2.0 with Oracle VM Agent 2.3.
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Oracle Virtual Server Agent Command Injection
Oracle VS Agent is prone to a remote command execution vulnerability because the software fails to adequately sanitize user-supplied input. Oracle VS Agent exposes through XML-RPC several functions. One of these functions is validate_master_ip, which receives fqdn as a parameter. This parameter is used in a system call without proper sanitization, allowing an attacker to inject arbitrary commands.
Mitigation:
Patch set 2.2.1 and above