Vulnerabilities > CVE-2010-3585 - Unspecified vulnerability in Oracle VM 2.2.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a third party researcher that this is related to the exposure of unspecified functions using XML-RPC.
Exploit-Db
description | Oracle VM Server Virtual Server Agent Command Injection. CVE-2010-3585. Remote exploit for linux platform |
id | EDB-ID:16915 |
last seen | 2016-02-02 |
modified | 2010-10-25 |
published | 2010-10-25 |
reporter | metasploit |
source | https://www.exploit-db.com/download/16915/ |
title | Oracle VM Server Virtual Server Agent Command Injection |
Metasploit
description | This module exploits a command injection flaw within Oracle\'s VM Server Virtual Server Agent (ovs-agent) service. By including shell meta characters within the second parameter to the 'utl_test_url' XML-RPC methodCall, an attacker can execute arbitrary commands. The service typically runs with root privileges. NOTE: Valid credentials are required to trigger this vulnerable. The username appears to be hardcoded as 'oracle', but the password is set by the administrator at installation time. |
id | MSF:EXPLOIT/UNIX/WEBAPP/ORACLE_VM_AGENT_UTL |
last seen | 2020-06-14 |
modified | 2017-07-24 |
published | 2010-10-22 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3585 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/unix/webapp/oracle_vm_agent_utl.rb |
title | Oracle VM Server Virtual Server Agent Command Injection |
Nessus
NASL family | OracleVM Local Security Checks |
NASL id | ORACLEVM_OVMSA-2010-0015.NASL |
description | The remote OracleVM system is missing necessary patches to address critical security updates : - Update changelog, fill CVE number. - Fix config-file access mode issue. - Fix file access vulnerability [orabug 10142417] (CVE-2010-3582) - Fix local privilege escalation [orabug 10142476] (CVE-2010-3584) - Fix ovs agent command injection [orabug 10146644] (CVE-2010-3585) - Fix validate master ip command injection [orabug 10142448] (CVE-2010-3583) - Add excutable mode to utils/upgrade.py. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 68878 |
published | 2013-07-15 |
reporter | This script is Copyright (C) 2013-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/68878 |
title | OracleVM 2.2 : ovs-agent (OVMSA-2010-0015) |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/95120/oracle_vm_agent_utl.rb.txt |
id | PACKETSTORM:95120 |
last seen | 2016-12-05 |
published | 2010-10-25 |
reporter | jduck |
source | https://packetstormsecurity.com/files/95120/Oracle-VM-Server-Virtual-Server-Agent-Command-Injection.html |
title | Oracle VM Server Virtual Server Agent Command Injection |
Seebug
bulletinFamily | exploit |
description | No description provided by source. |
id | SSV:71408 |
last seen | 2017-11-19 |
modified | 2014-07-01 |
published | 2014-07-01 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-71408 |
title | Oracle VM Server Virtual Server Agent Command Injection |
References
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html
- http://www.securityfocus.com/archive/1/514611/100/0/threaded
- http://www.securityfocus.com/archive/1/514611/100/0/threaded
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html
- http://www.us-cert.gov/cas/techalerts/TA10-287A.html