CVE-2009-1977

critical

Description

Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/51761

http://www.zerodayinitiative.com/advisories/ZDI-09-058/

http://www.vupen.com/english/advisories/2009/1900

http://www.securitytracker.com/id?1022565

http://www.securityfocus.com/bid/35672

http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html

http://secunia.com/advisories/35776

http://osvdb.org/55903

Details

Source: Mitre, NVD

Published: 2009-07-14

Updated: 2017-08-17

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical