Oracle.Application.Server.Arbitrary.System.Command.Execution

description-logoDescription

It indicates a possible exploit of a Servlet Command Execution vulnerability in Oracle Forms.
Oracle Forms starts forms (.fmx files) from arbitrary directories and executes them with Oracle or System user privileges. Attackers can execute arbitrary code by uploading a specially crafted .fmx file and referencing it using an absolute pathname argument.

affected-products-logoAffected Products

Oracle Forms 4.5 through 10g

Impact logoImpact

Compromise of the affected system.

recomended-action-logoRecommended Actions

Apply the appropriate patch from the vendor or upgrade to a non-vulnerable version if available.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2018-11-01 13.483 Sig Added
2018-10-16 13.473 Sig Added