DB: Oracle TimesTen In-Memory Database evtdump

This signature detects attempts to exploit a known vulnerability against Oracle TimesTen In-Memory Database. A successful attack allows attackers to execute arbitrary command with system privileges.

Extended Description

Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities affecting the following software: Oracle Database Oracle Secure Backup Oracle TimesTen In-Memory Database Oracle Application Server Oracle Collaboration Suite Oracle E-Business Suite Release Oracle Enterprise Manager Grid Control PeopleSoft Enterprise HRMS JD Edwards Tools Oracle WebLogic Server (formerly BEA WebLogic Server) Oracle WebLogic Portal (formerly BEA WebLogic Portal)

Affected Products

Bea_systems weblogic_server

References

BugTraq: 33177

CVE: CVE-2008-5440

Short Name
DB:ORACLE:EVTDUMP
Severity
Major
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
CVE-2008-5440 Database In-Memory Oracle TimesTen bid:33177 evtdump
Release Date
09/17/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3339
Port
TCP/17000
False Positive
Unknown
Vendors

Oracle

Bea_systems

CVSS Score

7.5

Found a potential security threat?