Oracle Secure Backup CVE-2009-1977 Remote Authentication Bypass Vulnerability
BID:35672
Info
Oracle Secure Backup CVE-2009-1977 Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 35672 |
| Class: | Unknown |
| CVE: |
CVE-2009-1977 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2009 12:00AM |
| Updated: | Sep 17 2009 03:20PM |
| Credit: | Oracle |
| Vulnerable: |
Oracle Secure Backup 10.3.0.1.0 Oracle Secure Backup 10.2.0.2 Oracle Secure Backup 10.1.0.3 Oracle Secure Backup 10.1.0.2 Oracle Secure Backup 10.1.0.1 |
| Not Vulnerable: |
Oracle Secure Backup 10.2.0.3 |
Discussion
Oracle Secure Backup CVE-2009-1977 Remote Authentication Bypass Vulnerability
Oracle Secure Backup is prone to a remote authentication-bypass vulnerability that can be exploited over the 'HTTP' protocol. An attacker doesn't require privileges to exploit this vulnerability.
The attacker can leverage this issue to gain administrative access to the affected application.
This vulnerability affects versions prior to Oracle Secure Backup 10.2.0.3.
Oracle Secure Backup is prone to a remote authentication-bypass vulnerability that can be exploited over the 'HTTP' protocol. An attacker doesn't require privileges to exploit this vulnerability.
The attacker can leverage this issue to gain administrative access to the affected application.
This vulnerability affects versions prior to Oracle Secure Backup 10.2.0.3.
Exploit / POC
Oracle Secure Backup CVE-2009-1977 Remote Authentication Bypass Vulnerability
Attackers can exploit this issue using common networking tools.
The following exploit is available:
Attackers can exploit this issue using common networking tools.
The following exploit is available:
Solution / Fix
Oracle Secure Backup CVE-2009-1977 Remote Authentication Bypass Vulnerability
Solution:
Vendor updates are available for Oracle Secure Backup 10.2 versions. However, updates for Oracle Secure Backup 10.3 versions do not appear to be available at this time. Please contact the vendor for details.
Solution:
Vendor updates are available for Oracle Secure Backup 10.2 versions. However, updates for Oracle Secure Backup 10.3 versions do not appear to be available at this time. Please contact the vendor for details.
References
Oracle Secure Backup CVE-2009-1977 Remote Authentication Bypass Vulnerability
References:
References:
- Oracle Homepage (Oracle)
- ZDI-09-058: Oracle Secure Backup Administration Server Authentication Bypass Vul (ZDI Disclosures
) - Oracle Critical Patch Update Advisory - July 2009 (Oracle)
- ZDI-09-058: Oracle Secure Backup Administration Server Authentication Bypass Vul (Zero Day Initiative)