PT-2011-3722 · Oracle · Oracle Secure Backup

Published

2011-07-20

·

Updated

2016-11-22

·

CVE-2011-2261

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Secure Backup version 10.3.0.3
Description The issue affects the confidentiality, integrity, and availability of the system. It is related to a command injection vulnerability in the validate login command, which could potentially allow for remote code execution.
Recommendations For Oracle Secure Backup version 10.3.0.3, apply the necessary patch or update to fix the command injection vulnerability in the validate login command. As a temporary workaround, consider restricting access to the validate login command to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-2261
ZDI-11-238

Affected Products

Oracle Secure Backup