Vulnerability record · CVE-2009-1978 · published 14 July 2009
CVE-2009-1978: Oracle Secure Backup unspecified flaw allows remote code execution
Oracle · Secure Backup
Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability in the Secure Backup component that affects confidentiality, integrity, and availability. Oracle's July 2009 CPU entry is vague, but an independent researcher claims remote authenticated users can execute arbitrary code with SYSTEM privileges via property_box.php.
Description
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows remote authenticated users to execute arbitrary code with SYSTEM privileges via vectors involving property_box.php.
AV:N/AC:L/Au:S/C:C/I:C/A:C
Automated analysis
high priorityThe CVSS 2.0 score is 9.0 with complete impact and a high EPSS percentile, but exploitation requires authentication and no public exploit is confirmed in the record.
What it is
Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability in the Secure Backup component that affects confidentiality, integrity, and availability. Oracle's July 2009 CPU entry is vague, but an independent researcher claims remote authenticated users can execute arbitrary code with SYSTEM privileges via property_box.php.
Impact
An attacker who can authenticate can potentially execute arbitrary code with SYSTEM privileges, gaining full control of the affected host. Even without the code execution claim, the flaw allows compromise of confidentiality, integrity, and availability.
Attack surface
The CVSS vector AV:N/AC:L/Au:S indicates the flaw is reachable over the network and requires authentication, with no user interaction. The claimed vector involves property_box.php, suggesting a web-facing component of Secure Backup.
Exploitation
CVE-2009-1978 is not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.64694, 99.2nd percentile), but the references carry no exploit tags, so public exploit availability is not confirmed by this record.
What to do
- Apply the Oracle July 2009 Critical Patch Update or a later Secure Backup release that addresses CVE-2009-1978.
- Restrict network access to Secure Backup management interfaces, including property_box.php, to trusted administrative networks.
- Enforce least privilege and strong authentication for Secure Backup accounts to limit the impact of authenticated exploitation.
- Monitor and audit Secure Backup logs for unexpected administrative actions or process creation with SYSTEM privileges.
Detection
- Review Secure Backup web server logs for unusual requests to property_box.php or other administrative endpoints.
- Alert on unexpected child processes spawned by the Secure Backup service or web server, especially those running as SYSTEM.
- Correlate authentication events with subsequent high-privilege process creation on Secure Backup hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1978 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1978), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.