Vulnerabilities > CVE-2009-1977 - Unspecified vulnerability in Oracle Secure Backup 10.2.0.3
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
D2sec
name | Oracle Secure Backup 10.3.0.1 RCE |
url | http://www.d2sec.com/exploits/oracle_secure_backup_10.3.0.1_rce.html |
Exploit-Db
description | Oracle Secure Backup Server 10.3.0.1.0 Auth Bypass/RCI Exploit. CVE-2009-1977. Remote exploit for windows platform |
id | EDB-ID:9652 |
last seen | 2016-02-01 |
modified | 2009-09-14 |
published | 2009-09-14 |
reporter | ikki |
source | https://www.exploit-db.com/download/9652/ |
title | Oracle Secure Backup Server 10.3.0.1.0 - Auth Bypass/RCI Exploit |
Metasploit
description | This module exploits an authentication bypass vulnerability in login.php in order to execute arbitrary code via a command injection vulnerability in property_box.php. This module was tested against Oracle Secure Backup version 10.3.0.1.0 (Win32). |
id | MSF:AUXILIARY/ADMIN/ORACLE/OSB_EXECQR2 |
last seen | 2019-12-13 |
modified | 2017-07-24 |
published | 2009-09-16 |
references | |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/admin/oracle/osb_execqr2.rb |
title | Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | OSB_FAKEOPTION_AUTH_BYPASS.NASL |
description | The remote web server is the Administration Server for Oracle Secure Backup, a centralized tape backup management software application. The installed version of Oracle Secure Backup allows a remote attacker to bypass authentication using a specially crafted username, such as |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 40989 |
published | 2009-09-14 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/40989 |
title | Oracle Secure Backup Administration Server Authentication Bypass |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/81262/osbs-bypass.txt |
id | PACKETSTORM:81262 |
last seen | 2016-12-05 |
published | 2009-09-15 |
reporter | Luca Carettoni |
source | https://packetstormsecurity.com/files/81262/Oracle-Secure-Backup-Server-Bypass-Command-Injection.html |
title | Oracle Secure Backup Server Bypass / Command Injection |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:12329 |
last seen | 2017-11-19 |
modified | 2009-09-16 |
published | 2009-09-16 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-12329 |
title | Oracle Secure Backup Server 10.3.0.1.0 Auth Bypass/RCI Exploit |
References
- http://osvdb.org/55903
- http://osvdb.org/55903
- http://secunia.com/advisories/35776
- http://secunia.com/advisories/35776
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.securityfocus.com/bid/35672
- http://www.securityfocus.com/bid/35672
- http://www.securitytracker.com/id?1022565
- http://www.securitytracker.com/id?1022565
- http://www.vupen.com/english/advisories/2009/1900
- http://www.vupen.com/english/advisories/2009/1900
- http://www.zerodayinitiative.com/advisories/ZDI-09-058/
- http://www.zerodayinitiative.com/advisories/ZDI-09-058/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51761
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51761