Title: Oracle Business Transaction Management Server FlashTunnelService WriteToFile Multiple Function Arbitrary File Creation
Info
Disclosure
Aug 07, 2012
Discovery
Unknown
Dates
Exploit
Aug 07, 2012
Solution
Unknown
Description
Oracle Business Transaction Management Server contains a flaw related to the FlashTunnelService web service component. The issue is triggered when the service fails to require authentication and exposes the WriteToFile and deleteFile functions. This may allow a remote attacker to create or delete arbitrary files.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Uncoordinated Disclosure
Solution
OSVDB is not aware of a solution for this vulnerability.