OSVDB ID: 85087

Title: Oracle Business Transaction Management Server FlashTunnelService WriteToFile Multiple Function Arbitrary File Creation

Info

Disclosure

Aug 07, 2012

Discovery

Unknown

Dates

Exploit

Aug 07, 2012

Solution

Unknown

Description

Oracle Business Transaction Management Server contains a flaw related to the FlashTunnelService web service component. The issue is triggered when the service fails to require authentication and exposes the WriteToFile and deleteFile functions. This may allow a remote attacker to create or delete arbitrary files.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Solution Unknown
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure

Solution

OSVDB is not aware of a solution for this vulnerability.

Products

Oracle Corporation

Business Transaction Management Server

12.1.0.2.7

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85087