Oracle Endeca Server CVE-2013-3763 Remote Code Execution Vulnerability
BID:61217
Info
Oracle Endeca Server CVE-2013-3763 Remote Code Execution Vulnerability
| Bugtraq ID: | 61217 |
| Class: | Unknown |
| CVE: |
CVE-2013-3763 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2013 12:00AM |
| Updated: | Aug 26 2013 08:10AM |
| Credit: | Oracle |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle Endeca Server CVE-2013-3763 Remote Code Execution Vulnerability
Oracle Endeca Server is prone to a remote code-execution vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'Software' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the current process.
This vulnerability affects the following supported versions:
7.4.0, 7.5.1.1
Oracle Endeca Server is prone to a remote code-execution vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'Software' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the current process.
This vulnerability affects the following supported versions:
7.4.0, 7.5.1.1
Exploit / POC
Oracle Endeca Server CVE-2013-3763 Remote Code Execution Vulnerability
The following Metasploit exploit code is available:
The following Metasploit exploit code is available:
Solution / Fix
Oracle Endeca Server CVE-2013-3763 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle Endeca Server CVE-2013-3763 Remote Code Execution Vulnerability
References:
References:
- Oracle Homepage (Oracle)