Release date:
Updated on:
Affected Systems:
Oracle Audit Vault 10.2.3.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45844
Cve id: CVE-2010-4449
Oracle Audit Vault is an automated software and service for enterprise database Audit and monitoring.
Oracle Audit Vault has a security vulnerability when processing requests. Remote attackers can exploit this vulnerability to control affected systems.
When Oracle Audit vaultprocesses an action.exe cute request, because the invalid parameter verification in the av component has an error, You can execute arbitrary code through a specially crafted service request (default port 5700/TCP.
<* Source: 1c239c43f521145fa8417d64a9c32243
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Oracle
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.oracle.com