EIP-2026-119009
PRE-CVEOracle Business Transaction Management Server 12.1.0.2.7 FlashTunnelService - Remote File Deletion
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119009. PoCs published by rgod.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in Oracle Business Transaction Management Server's FlashTunnelService, allowing unauthenticated remote file deletion via a SOAP request. The PoC sends a crafted SOAP envelope to delete arbitrary files on the target system.
Description
Oracle Business Transaction Management Server 12.1.0.2.7 FlashTunnelService - Remote File Deletion
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in Oracle Business Transaction Management Server's FlashTunnelService, allowing unauthenticated remote file deletion via a SOAP request. The PoC sends a crafted SOAP envelope to delete arbitrary files on the target system.