← Vulnerability feed

Vulnerability record · CVE-2009-1977 · published 14 July 2009

CVE-2009-1977: Oracle Secure Backup authentication bypass and unspecified remote compromise

Oracle · Secure Backup

Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availability. Oracle's advisory gives no technical detail, and an independent researcher claims the flaw allows authentication bypass through the username parameter and login.php, which Oracle has not confirmed.

10.0 CVSS 2.0 High EPSS 73% · top 0.6%
10.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and full confidentiality, integrity, and availability impact, plus a very high EPSS percentile, warrants critical handling despite thin technical detail.

What it is

Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availability. Oracle's advisory gives no technical detail, and an independent researcher claims the flaw allows authentication bypass through the username parameter and login.php, which Oracle has not confirmed.

Impact

An unauthenticated remote attacker could bypass authentication and gain full control over the affected component, compromising confidentiality, integrity, and availability.

Attack surface

The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicates the flaw is reachable over the network with no authentication and no user interaction. The researcher's claim points to the login.php endpoint and username parameter, but Oracle has not confirmed this path.

Exploitation

The record is not listed in CISA KEV and no reference carries an exploit tag, though EPSS gives a 30-day probability of 0.72638 (99.4th percentile), suggesting high predicted exploitation activity. No public exploit or in-the-wild use is documented in this record.

What to do

  • Apply the Oracle July 2009 Critical Patch Update for Secure Backup 10.2.0.3 or upgrade to a supported release.
  • Restrict network access to Secure Backup management and login interfaces to trusted hosts only.
  • Monitor and audit authentication attempts against login.php and the username parameter for anomalies.
  • If the product is end-of-life or cannot be patched, isolate it from untrusted networks or retire it.

Detection

  • Review Secure Backup and web server logs for login.php requests with unusual or malformed username values.
  • Alert on successful authentications from unexpected source IPs or outside normal administrative windows.
  • Baseline normal Secure Backup traffic and flag deviations in request volume or parameter patterns to login endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1977 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed10.0CVE-2011-2261Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.3.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.2%10.0CVE-2010-0907Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 7.5%10.0CVE-2010-0898Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 2.9%10.0CVE-2010-0072Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, i…EPSS 6.1%10.0CVE-2008-4006Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.4%10.0CVE-2008-5444Oracle Secure Backup remote unspecified flaw in 10.2.0.2CVE-2008-5444 is an unspecified vulnerability in the Oracle Secure Backup component of Oracle Secure Backup 10.2.0.2. The record gives no detail on t…EPSS 61%analysed10.0CVE-2008-5448Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, i…EPSS 41%

Source: NIST National Vulnerability Database (record CVE-2009-1977), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.