Home→Descriptions→SA50642
| Secunia ID | |
| Release Date |
17 Sep 2012 |
| Criticality | |
| Solution Status |
Unpatched |
| Software |
Oracle Business Transaction Management (BTM) 12.x |
| Where | |
| Impact |
System accessThis covers vulnerabilities where malicious people are able to gain system access and execute arbitrary code with the privileges of a local user. |
| Description |
A vulnerability has been reported in Oracle Business Transaction Management, which can be exploited by malicious people to compromise a vulnerable system. Input passed to the "writeToFile()" method in the FlashTunnelService SOAP interface is not properly verified before being used to store files. This can be exploited to upload arbitrary files via directory traversal sequences. The vulnerability is reported in version 12.1.0.7. Other versions may also be affected. |
| Solution |
No official solution is currently available. |
| Reported by |
Andrea Micalizzi aka rgod. |
| Original Advisory |