Vulnerability record · CVE-2009-1977 · published 14 July 2009
CVE-2009-1977: Oracle Secure Backup authentication bypass and unspecified remote compromise
Oracle · Secure Backup
Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availability. Oracle's advisory gives no technical detail, and an independent researcher claims the flaw allows authentication bypass through the username parameter and login.php, which Oracle has not confirmed.
Description
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus a very high EPSS percentile, warrants critical handling despite thin technical detail.
What it is
Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availability. Oracle's advisory gives no technical detail, and an independent researcher claims the flaw allows authentication bypass through the username parameter and login.php, which Oracle has not confirmed.
Impact
An unauthenticated remote attacker could bypass authentication and gain full control over the affected component, compromising confidentiality, integrity, and availability.
Attack surface
The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The researcher's claim points to the login.php endpoint and username parameter, but Oracle has not confirmed this path.
Exploitation
The record is not listed in CISA KEV and no reference carries an exploit tag, though EPSS gives a 30-day probability of 0.72638 (99.4th percentile), suggesting high predicted exploitation activity. No public exploit or in-the-wild use is documented in this record.
What to do
- Apply the Oracle July 2009 Critical Patch Update for Secure Backup 10.2.0.3 or upgrade to a supported release.
- Restrict network access to Secure Backup management and login interfaces to trusted hosts only.
- Monitor and audit authentication attempts against login.php and the username parameter for anomalies.
- If the product is end-of-life or cannot be patched, isolate it from untrusted networks or retire it.
Detection
- Review Secure Backup and web server logs for login.php requests with unusual or malformed username values.
- Alert on successful authentications from unexpected source IPs or outside normal administrative windows.
- Baseline normal Secure Backup traffic and flag deviations in request volume or parameter patterns to login endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1977 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.