EIP-2026-102347
PRE-CVEOracle Business Transaction Management FlashTunnelService - Remote Code Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102347. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a directory traversal and arbitrary file upload vulnerability in Oracle Business Transaction Management 12.1.0.7 via the FlashTunnelService SOAP web service. It achieves remote code execution by uploading a JSP payload or leveraging Windows Management Instrumentation (WMI) for execution.
Description
Oracle Business Transaction Management FlashTunnelService - Remote Code Execution (Metasploit)
Exploits (1)
This Metasploit module exploits a directory traversal and arbitrary file upload vulnerability in Oracle Business Transaction Management 12.1.0.7 via the FlashTunnelService SOAP web service. It achieves remote code execution by uploading a JSP payload or leveraging Windows Management Instrumentation (WMI) for execution.