CVE-2009-1977
Oracle Secure Backup 10.2.0.3 - Info Disclosure
Title source: llmDescription
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php.
Exploits (2)
metasploit
WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/oracle/osb_execqr2.rb
References (8)
Scores
EPSS
0.8514
EPSS Percentile
99.3%
Classification
Status
draft
Affected Products (1)
oracle/secure_backup
Timeline
Published
Jul 14, 2009
Tracked Since
Feb 18, 2026