Oracle Secure Backup CVE-2009-1978 Arbitrary Command Execution Vulnerability
BID:35678
Info
Oracle Secure Backup CVE-2009-1978 Arbitrary Command Execution Vulnerability
| Bugtraq ID: | 35678 |
| Class: | Unknown |
| CVE: |
CVE-2009-1978 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2009 12:00AM |
| Updated: | Sep 17 2009 03:31PM |
| Credit: | Oracle |
| Vulnerable: |
Oracle Secure Backup 10.3.0.1.0 Oracle Secure Backup 10.2.0.2 Oracle Secure Backup 10.1.0.3 Oracle Secure Backup 10.1.0.2 Oracle Secure Backup 10.1.0.1 |
| Not Vulnerable: | |
Discussion
Oracle Secure Backup CVE-2009-1978 Arbitrary Command Execution Vulnerability
Oracle Secure Backup is prone to a remote arbitrary command-execution vulnerability that can be exploited over the 'HTTP' protocol. An authenticated attacker with 'Valid Session' privileges can exploit this issue.
The attacker can leverage this issue to execute arbitrary commands with Oracle SYSTEM account privileges.
Oracle Secure Backup is prone to a remote arbitrary command-execution vulnerability that can be exploited over the 'HTTP' protocol. An authenticated attacker with 'Valid Session' privileges can exploit this issue.
The attacker can leverage this issue to execute arbitrary commands with Oracle SYSTEM account privileges.
Exploit / POC
Oracle Secure Backup CVE-2009-1978 Arbitrary Command Execution Vulnerability
Attackers can exploit this issue using common networking tools.
The following exploit is available:
Attackers can exploit this issue using common networking tools.
The following exploit is available:
Solution / Fix
Oracle Secure Backup CVE-2009-1978 Arbitrary Command Execution Vulnerability
Solution:
Vendor updates are available for Oracle Secure Backup 10.2 versions. However, updates for Oracle Secure Backup 10.3 versions do not appear to be available at this time. Please contact the vendor for details.
Solution:
Vendor updates are available for Oracle Secure Backup 10.2 versions. However, updates for Oracle Secure Backup 10.3 versions do not appear to be available at this time. Please contact the vendor for details.
References
Oracle Secure Backup CVE-2009-1978 Arbitrary Command Execution Vulnerability
References:
References:
- Oracle Homepage (Oracle)
- ZDI-09-059: Oracle Secure Backup Administration Server Multiple Command Injectio (ZDI Disclosures
) - Oracle Critical Patch Update Advisory - July 2009 (Oracle)
- ZDI-09-059: Oracle Secure Backup Administration Server Multiple Command Injectio (Zero Day Initiative)