CVE-2013-3764
Oracle Endeca Server attachDataStore SOAP Request Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3763.
Vulnerabilidad sin especificar en el componente Oracle Endeca Server en Oracle Fusion Middleware 7.4.0 y7.5.1.1, permite a usuarios autenticados remotamente comprometer la confidencialidad e integridad a través de vectores desconocidos. Vulnerabilidad distinta de CVE-2013-3763.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Endeca Server. Authentication is not required to exploit this vulnerability.
The specific flaw exists in the handling of requests to the controlSoapBinding web service. This service exposes the attachDataStore method which contains a directory traversal flaw that allows attackers to create files at arbitrary locations with attacker controlled data. This can be leveraged by an attacker gain to remote code execution under the context of the current user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-06-03 CVE Reserved
- 2013-07-17 CVE Published
- 2024-06-06 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1028801 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpujuly2013-1899826.html | 2013-08-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 7.4.0 Search vendor "Oracle" for product "Fusion Middleware" and version "7.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Fusion Middleware Search vendor "Oracle" for product "Fusion Middleware" | 7.5.1.1 Search vendor "Oracle" for product "Fusion Middleware" and version "7.5.1.1" | - |
Affected
|