CVE-2009-0993
Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a format string vulnerability that allows remote attackers to execute arbitrary code via format string specifiers in an HTTP POST URI, which are not properly handled when logging to opmn/logs/opmn.log.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.95% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server
- Source
- secalert_us@oracle.com
References
- http://secunia.com/advisories/34693
- http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html
- http://www.securityfocus.com/archive/1/502683/100/0/threaded
- http://www.securityfocus.com/bid/34461
- http://www.securitytracker.com/id?1022055
- http://www.us-cert.gov/cas/techalerts/TA09-105A.htmlUS Government Resource
- http://www.zerodayinitiative.com/advisories/ZDI-09-017
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50030
- http://secunia.com/advisories/34693
- http://www.oracle.com/technetwork/topics/security/cpuapr2009-099563.html
- http://www.securityfocus.com/archive/1/502683/100/0/threaded
- http://www.securityfocus.com/bid/34461
- http://www.securitytracker.com/id?1022055
- http://www.us-cert.gov/cas/techalerts/TA09-105A.htmlUS Government Resource
- http://www.zerodayinitiative.com/advisories/ZDI-09-017
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50030
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.