J2EE/RI Pointbase Database Remote Command Execution Vulnerability
BID:9230
Info
J2EE/RI Pointbase Database Remote Command Execution Vulnerability
| Bugtraq ID: | 9230 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2003 12:00AM |
| Updated: | Dec 16 2003 12:00AM |
| Credit: | Discovery is credited to Marc Schoenefeld <[email protected]>. |
| Vulnerable: |
Sun JDK (Windows Production Release) 1.4.2 _02 Sun J2EE/RI (Windows) 1.4 |
| Not Vulnerable: | |
Discussion
J2EE/RI Pointbase Database Remote Command Execution Vulnerability
A vulnerability has been reported in the J2EE/RI (Reference Implementation) Pointbase 4.6 database that could permit remote attackers to execute arbitrary commands on a system hosting the software. This issue may reportedly be exploited through a malicious SQL statement that will cause an executable on the host file system to be run. Denial of service attacks and exposure of sensitive information may also be the result of successful exploitation.
This vulnerability is similar in nature to the issue described in BID 8773. The vulnerability was reported for J2EE/RI 1.4 on Windows platforms. Other versions and releases for different platforms are also likely affected.
A vulnerability has been reported in the J2EE/RI (Reference Implementation) Pointbase 4.6 database that could permit remote attackers to execute arbitrary commands on a system hosting the software. This issue may reportedly be exploited through a malicious SQL statement that will cause an executable on the host file system to be run. Denial of service attacks and exposure of sensitive information may also be the result of successful exploitation.
This vulnerability is similar in nature to the issue described in BID 8773. The vulnerability was reported for J2EE/RI 1.4 on Windows platforms. Other versions and releases for different platforms are also likely affected.
Exploit / POC
J2EE/RI Pointbase Database Remote Command Execution Vulnerability
This issue can be exploited using a malicious SQL statement.
This issue can be exploited using a malicious SQL statement.
Solution / Fix
J2EE/RI Pointbase Database Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.