Vulnerabilities > CVE-2013-3763 - Remote Code Execution vulnerability in Oracle Fusion Middleware 7.4.0/7.5.1.1

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
oracle
exploit available
metasploit

Summary

Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3764.

Vulnerable Configurations

Part Description Count
Application
Oracle
2

Exploit-Db

descriptionOracle Endeca Server Remote Command Execution. CVE-2013-3763. Remote exploit for windows platform
idEDB-ID:27877
last seen2016-02-03
modified2013-08-26
published2013-08-26
reportermetasploit
sourcehttps://www.exploit-db.com/download/27877/
titleOracle Endeca Server Remote Command Execution

Metasploit

descriptionThis module exploits a command injection vulnerability on the Oracle Endeca Server 7.4.0. The vulnerability exists on the createDataStore method from the controlSoapBinding web service. The vulnerable method only exists on the 7.4.0 branch and isn't available on the 7.5.5.1 branch. In addition, the injection has been found to be Windows specific. This module has been tested successfully on Endeca Server 7.4.0.787 over Windows 2008 R2 (64 bits).
idMSF:EXPLOIT/WINDOWS/HTTP/ORACLE_ENDECA_EXEC
last seen2020-06-13
modified2017-07-24
published2013-08-21
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/windows/http/oracle_endeca_exec.rb
titleOracle Endeca Server Remote Command Execution

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/122949/oracle_endeca_exec.rb.txt
idPACKETSTORM:122949
last seen2016-12-05
published2013-08-24
reporterrgod
sourcehttps://packetstormsecurity.com/files/122949/Oracle-Endeca-Server-Remote-Command-Execution.html
titleOracle Endeca Server Remote Command Execution

Saint

bid61217
descriptionOracle Endeca Server createDataStore method command execution
osvdb95269
titleoracle_endeca_createdatastore
typeremote