Oracle Endeca Server CVE-2013-3764 Remote Code Execution Vulnerability
BID:61224
Info
Oracle Endeca Server CVE-2013-3764 Remote Code Execution Vulnerability
| Bugtraq ID: | 61224 |
| Class: | Unknown |
| CVE: |
CVE-2013-3764 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2013 12:00AM |
| Updated: | Aug 14 2013 04:46PM |
| Credit: | Andrea Micalizzi aka rgod |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle Endeca Server CVE-2013-3764 Remote Code Execution Vulnerability
Oracle Endeca Server is prone to a remote code-execution vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'Software' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the current user.
This vulnerability affects the following supported versions:
7.4.0, 7.5.1.1
Oracle Endeca Server is prone to a remote code-execution vulnerability.
The vulnerability can be exploited over the 'HTTP' protocol. The 'Software' sub component is affected.
An attacker can exploit this issue to execute arbitrary code in the context of the current user.
This vulnerability affects the following supported versions:
7.4.0, 7.5.1.1
Exploit / POC
Oracle Endeca Server CVE-2013-3764 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle Endeca Server CVE-2013-3764 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle Endeca Server CVE-2013-3764 Remote Code Execution Vulnerability
References:
References:
- Oracle Homepage (Oracle)