DB: Oracle Secure Backup Administration Server login.php Command Injection
This signature detects attempts to exploit a known vulnerability against Oracle Secure Backup Administration Server. Attackers can execute arbitrary command with server privilege.
Extended Description
Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities affecting the following software: Oracle Database Oracle Secure Backup Oracle TimesTen In-Memory Database Oracle Application Server Oracle Collaboration Suite Oracle E-Business Suite Release Oracle Enterprise Manager Grid Control PeopleSoft Enterprise HRMS JD Edwards Tools Oracle WebLogic Server (formerly BEA WebLogic Server) Oracle WebLogic Portal (formerly BEA WebLogic Portal)
Affected Products
Bea_systems weblogic_server
References
BugTraq: 33177
CVE: CVE-2008-5448
URL: http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujan2009.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Oracle
Bea_systems
10.0