PT-2010-2629 · Oracle · Oracle Secure Backup

Published

2010-07-13

·

Updated

2012-10-23

·

CVE-2010-0906

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Secure Backup version 10.3.0.1
Description The issue affects confidentiality, integrity, and availability. It is related to a command injection remote code execution vulnerability in the Oracle Secure Backup Administration. The objectname and selector parameters are involved.
Recommendations For Oracle Secure Backup version 10.3.0.1, consider restricting access to the administration interface to minimize the risk of exploitation until a patch is available. As a temporary workaround, avoid using the objectname and selector parameters in the Oracle Secure Backup Administration until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-0906
ZDI-10-120
ZDI-10-121
ZDI-10-122

Affected Products

Oracle Secure Backup