CVE-2013-3763
Oracle Endeca Server createDataStore SOAP Request Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3764.
Vulnerabilidad no especificada en el componente Oracle Endeca Server en Oracle Fusion Middleware v7.4.0 y v7.5.1.1 permite a atacantes remotos afectar la confidencialidad e integridad mediante vectores desconocidos, una vulnerabilidad diferente a CVE-2013-3764.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Endeca Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists in the handling of requests to the controlSoapBinding web service. This service exposes the createDataStore method which contains a flaw that allows attackers to inject arbitrary operating system commands. This can be leveraged by an attacker gain to remote code execution under the context of the current process.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-06-03 CVE Reserved
- 2013-07-17 CVE Published
- 2013-08-26 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1028801 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-13-190 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/27877 | 2013-08-26 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html | 2013-09-11 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 7.4.0 Search vendor "Oracle" for product "Fusion Middleware" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 7.5.1.1 Search vendor "Oracle" for product "Fusion Middleware" and version "7.5.1.1" | - |
Affected
|