Oracle Secure Backup 'validate_login' Command Injection Remote Code Execution Vulnerability
BID:48752
Info
Oracle Secure Backup 'validate_login' Command Injection Remote Code Execution Vulnerability
| Bugtraq ID: | 48752 |
| Class: | Unknown |
| CVE: |
CVE-2011-2261 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2011 12:00AM |
| Updated: | Jul 21 2011 08:10PM |
| Credit: | Tenable Network Security |
| Vulnerable: |
Oracle Secure Backup 10.3.0.3 |
| Not Vulnerable: | |
Discussion
Oracle Secure Backup 'validate_login' Command Injection Remote Code Execution Vulnerability
Oracle Secure Backup is prone to a remote code-execution vulnerability.
Successful exploits will allow an attacker to run arbitrary code in the context of the web server process. Failed attacks will cause denial-of-service conditions.
This vulnerability affects the following supported versions:
10.3.0.3
Oracle Secure Backup is prone to a remote code-execution vulnerability.
Successful exploits will allow an attacker to run arbitrary code in the context of the web server process. Failed attacks will cause denial-of-service conditions.
This vulnerability affects the following supported versions:
10.3.0.3
Exploit / POC
Oracle Secure Backup 'validate_login' Command Injection Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Secure Backup 'validate_login' Command Injection Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Secure Backup 'validate_login' Command Injection Remote Code Execution Vulnerability
References:
References:
- ZDI-11-238: Oracle Secure Backup validate_login Command Injection Remote Code Ex (TippingPoint Zero Day Initiative)
- Oracle Critical Patch Update Advisory - July 2011 (Oracle)