Update Protection against Multiple Oracle Secure Backup Administration Server Command Injection Vulnerabilities
| Check Point Reference: | CPAI-2009-031 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Secunia Advisory: SA33525 | |
| Industry Reference(s): | CVE-2008-5448 CVE-2008-4006 CVE-2008-5449 |
|
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Oracle Secure Backup 10.1.0.3 Oracle Secure Backup 10.2.0.2 | ||
| Vulnerability Description Several command injection vulnerabilities were reported in Oracle Secure Backup Administration Server. The Server allows for single point of management of data present on network attached storage (NAS) devices and distributed hosts which may have different operating systems. Remote unauthenticated attackers can exploit these vulnerabilities by sending a crafted HTTP request to the target host. Successful exploitation could allow for arbitrary command execution in the security context of the user running a vulnerable installation of Oracle Secure Backup. |
||
|
Update/Patch Available Apply patches: Oracle Critical Patch Update Advisory |
|
|
Vulnerability Details Oracle Secure Backup Server provides a web-based console for various administrative tasks. The server side script which handles the login for providing access to the console is called login.php. The vulnerabilities are due to lack of sanitation of user supplied parameters when processing HTTP requests sent to PHP program login.php. Remote unauthenticated attackers can exploit this vulnerability by sending a crafted HTTP request to the target host. |
Protection Overview
By enabling this protection, SmartDefense will detect and block attempts to exploit the command injection vulnerabilities in Oracle Secure Backup.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.