EIP-2026-119008
PRE-CVEOracle Business Transaction Management Server 12.1.0.2.7 - FlashTunnelService WriteToFile Message Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119008. PoCs published by rgod.
AI-analyzed exploit summary This exploit targets a directory traversal vulnerability in Oracle Business Transaction Management Server's FlashTunnelService, allowing unauthenticated remote code execution via arbitrary file write. The PoC demonstrates writing a malicious JSP file to the server's web root.
Description
Oracle Business Transaction Management Server 12.1.0.2.7 - FlashTunnelService WriteToFile Message Remote Code Execution
Exploits (1)
This exploit targets a directory traversal vulnerability in Oracle Business Transaction Management Server's FlashTunnelService, allowing unauthenticated remote code execution via arbitrary file write. The PoC demonstrates writing a malicious JSP file to the server's web root.