CVE-2016-0451
Oracle GoldenGate File Upload Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0452.
Vulnerabilidad no especificada en el componente Oracle GoldenGate en Oracle GoldenGate 11.2 y 12.1.2 permite a atacantes remotos afectar a la confidencialidad, la integridad y la disponibilidad a través de vectores desconocidos, una vulnerabilidad diferente a CVE-2016-0452.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle GoldenGate. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the GoldenGate mgr process, which listens on TCP port 7809. By default, the process does not authenticate connecting machines prior to allowing them to write arbitrary files at arbitrary locations on the server. An attacker could leverage this vulnerability to execute arbitrary code under the context of the current user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-09 CVE Reserved
- 2016-01-21 CVE Published
- 2022-07-18 First Exploit
- 2024-08-05 CVE Updated
- 2024-09-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/81125 | Third Party Advisory | |
http://www.zerodayinitiative.com/advisories/ZDI-16-022 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/rwincey/Oracle-GoldenGate---CVE-2016-0451 | 2022-07-18 | |
https://redr2e.com/cve-to-poc-cve-2016-0451 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html | 2017-01-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Goldengate Search vendor "Oracle" for product "Goldengate" | 11.2 Search vendor "Oracle" for product "Goldengate" and version "11.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate Search vendor "Oracle" for product "Goldengate" | 12.1.2 Search vendor "Oracle" for product "Goldengate" and version "12.1.2" | - |
Affected
|