← Vulnerability feed

Vulnerability record · CVE-2010-0072 · published 13 January 2010

CVE-2010-0072: Oracle secure backup vulnerability

Oracle · Secure Backup

Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a buffer overflow in observiced.exe that allows remote attackers to execute arbitrary code via vectors related to a "reverse lookup of connections" to TCP port 10000.

10.0 CVSS 2.0 High EPSS 6.1% · top 6.9%
10.0CVSS 2.0 base score
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is a buffer overflow in observiced.exe that allows remote attackers to execute arbitrary code via vectors related to a "reverse lookup of connections" to TCP port 10000.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0072 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed10.0CVE-2011-2261Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.3.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.2%10.0CVE-2010-0907Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 7.5%10.0CVE-2010-0898Oracle secure backup vulnerabilityUnspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown…EPSS 2.9%10.0CVE-2009-1977Oracle Secure Backup authentication bypass and unspecified remote compromiseOracle Secure Backup 10.2.0.3 contains an unspecified vulnerability that remote attackers can use to affect confidentiality, integrity, and availabil…EPSS 73%analysed10.0CVE-2008-4006Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, i…EPSS 3.4%10.0CVE-2008-5444Oracle Secure Backup remote unspecified flaw in 10.2.0.2CVE-2008-5444 is an unspecified vulnerability in the Oracle Secure Backup component of Oracle Secure Backup 10.2.0.2. The record gives no detail on t…EPSS 61%analysed10.0CVE-2008-5448Oracle secure backup vulnerabilityUnspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, i…EPSS 41%

Source: NIST National Vulnerability Database (record CVE-2010-0072), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.