← Vulnerability feed

Vulnerability record · CVE-2008-5444 · published 14 January 2009

CVE-2008-5444: Oracle Secure Backup remote unspecified flaw in 10.2.0.2

Oracle · Secure Backup

CVE-2008-5444 is an unspecified vulnerability in the Oracle Secure Backup component of Oracle Secure Backup 10.2.0.2. The record gives no detail on the root cause or the affected code path, only that it is distinct from CVE-2008-5448 and CVE-2008-5449. Because the flaw is unauthenticated and network reachable with full confidentiality, integrity and availability impact, it matters to any organization still running this version.

10.0 CVSS 2.0 High EPSS 61% · top 0.9%
10.0CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and CVE-2008-5449.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe CVSS 2.0 score is 10.0 with network reachability and no authentication, but the record lacks root-cause detail and there is no confirmed exploitation, so it is high rather than critical.

What it is

CVE-2008-5444 is an unspecified vulnerability in the Oracle Secure Backup component of Oracle Secure Backup 10.2.0.2. The record gives no detail on the root cause or the affected code path, only that it is distinct from CVE-2008-5448 and CVE-2008-5449. Because the flaw is unauthenticated and network reachable with full confidentiality, integrity and availability impact, it matters to any organization still running this version.

Impact

A remote attacker can affect confidentiality, integrity and availability of the affected system, which per the CVSS 2.0 vector means full compromise of those three properties. The record does not state what data or functions are specifically exposed.

Attack surface

Reachable over the network with no authentication required (AV:N/AC:L/Au:N), based on the CVSS vector. The description does not say whether user interaction is needed, and no attack path is described.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.60625, 99.1st percentile), but reference tags only include vendor advisory, third-party advisory and VDB entries, with no public exploit or PoC tag, so active exploitation is not confirmed by this record.

What to do

  • Apply the Oracle Critical Patch Update from January 2009 referenced in the vendor advisory, or upgrade Oracle Secure Backup past 10.2.0.2.
  • If patching is not immediately possible, restrict network access to Oracle Secure Backup services to trusted management hosts only.
  • Place the backup server behind firewall rules and do not expose its management or data ports to untrusted networks.
  • Monitor Oracle advisories for the related CVEs (CVE-2008-5448, CVE-2008-5449) since they affect the same component and may share exposure.
  • Inventory hosts still running Oracle Secure Backup 10.2.0.2 and treat them as end-of-life until upgraded.

Detection

  • Review Oracle Secure Backup logs for unexpected remote connections or authentication anomalies from untrusted source addresses.
  • Baseline normal client and management traffic to the backup server and alert on new or unusual source IPs and ports.
  • Monitor for post-exploitation behavior on backup hosts, such as new processes, file changes or outbound connections from the backup service account.
  • Use network monitoring to flag scanning or connection attempts against Oracle Secure Backup ports from outside the expected management network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-5444 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed10.0CVE-2011-2261Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.3.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.2%10.0CVE-2010-0907Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 7.5%10.0CVE-2010-0898Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 2.9%10.0CVE-2010-0072Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, i…EPSS 6.1%10.0CVE-2009-1977Oracle Secure Backup authentication bypass and unspecified remote compromiseOracle Secure Backup 10.2.0.3 contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availabil…EPSS 73%analysed10.0CVE-2008-4006Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.4%10.0CVE-2008-5448Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, i…EPSS 41%

Source: NIST National Vulnerability Database (record CVE-2008-5444), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.