← Vulnerability feed

Vulnerability record · CVE-2009-1978 · published 14 July 2009

CVE-2009-1978: Oracle Secure Backup unspecified flaw allows remote code execution

Oracle · Secure Backup

Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability in the Secure Backup component that affects confidentiality, integrity, and availability. Oracle's July 2009 CPU entry is vague, but an independent researcher claims remote authenticated users can execute arbitrary code with SYSTEM privileges via property_box.php.

9.0 CVSS 2.0 High EPSS 65% · top 0.8%
9.0CVSS 2.0 base score
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows remote authenticated users to execute arbitrary code with SYSTEM privileges via vectors involving property_box.php.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe CVSS 2.0 score is 9.0 with complete impact and a high EPSS percentile, but exploitation requires authentication and no public exploit is confirmed in the record.

What it is

Oracle Secure Backup 10.2.0.3 contains an unspecified vulnerability in the Secure Backup component that affects confidentiality, integrity, and availability. Oracle's July 2009 CPU entry is vague, but an independent researcher claims remote authenticated users can execute arbitrary code with SYSTEM privileges via property_box.php.

Impact

An attacker who can authenticate can potentially execute arbitrary code with SYSTEM privileges, gaining full control of the affected host. Even without the code execution claim, the flaw allows compromise of confidentiality, integrity, and availability.

Attack surface

The CVSS vector AV:N/AC:L/Au:S indicates the flaw is reachable over the network and requires authentication, with no user interaction. The claimed vector involves property_box.php, suggesting a web-facing component of Secure Backup.

Exploitation

CVE-2009-1978 is not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.64694, 99.2nd percentile), but the references carry no exploit tags, so public exploit availability is not confirmed by this record.

What to do

  • Apply the Oracle July 2009 Critical Patch Update or a later Secure Backup release that addresses CVE-2009-1978.
  • Restrict network access to Secure Backup management interfaces, including property_box.php, to trusted administrative networks.
  • Enforce least privilege and strong authentication for Secure Backup accounts to limit the impact of authenticated exploitation.
  • Monitor and audit Secure Backup logs for unexpected administrative actions or process creation with SYSTEM privileges.

Detection

  • Review Secure Backup web server logs for unusual requests to property_box.php or other administrative endpoints.
  • Alert on unexpected child processes spawned by the Secure Backup service or web server, especially those running as SYSTEM.
  • Correlate authentication events with subsequent high-privilege process creation on Secure Backup hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-1978 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed10.0CVE-2011-2261Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.3.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.2%10.0CVE-2010-0907Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 7.5%10.0CVE-2010-0898Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 2.9%10.0CVE-2010-0072Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, i…EPSS 6.1%10.0CVE-2009-1977Oracle Secure Backup authentication bypass and unspecified remote compromiseOracle Secure Backup 10.2.0.3 contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availabil…EPSS 73%analysed10.0CVE-2008-4006Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.4%10.0CVE-2008-5444Oracle Secure Backup remote unspecified flaw in 10.2.0.2CVE-2008-5444 is an unspecified vulnerability in the Oracle Secure Backup component of Oracle Secure Backup 10.2.0.2. The record gives no detail on t…EPSS 61%analysed

Source: NIST National Vulnerability Database (record CVE-2009-1978), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.