Lucene search

K
saintSAINT CorporationSAINT:D76D2B4D380AEDB115A75D02AF468F0C
HistorySep 04, 2013 - 12:00 a.m.

Oracle Endeca Server createDataStore method command execution

2013-09-0400:00:00
SAINT Corporation
download.saintcorporation.com
24

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

EPSS

0.972

Percentile

99.8%

Added: 09/04/2013
CVE: CVE-2013-3763
BID: 61217
OSVDB: 95269

Background

Oracle Endeca Server is a hybrid search-analytical database.

Problem

A vulnerability in the **controlSoapBinding** service allows remote attackers to execute arbitrary commands by sending a request for the **createDataStore** method with a specially crafted **dataFiles** parameter.

Resolution

Apply the patch referenced in the July 2013 Critical Patch Update.

References

<http://www.zerodayinitiative.com/advisories/ZDI-13-190/&gt;

Limitations

Exploit works on Oracle Endeca Server 7.4.0 on Windows Server 2008 R2 SP1 (DEP OptOut).

Platforms

Windows

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

EPSS

0.972

Percentile

99.8%