Bird_banner_small4
Oracle TimesTen In-Memory Database HTTP Request Denial of Service
FSCID FSC20100201-03
CVEID(s)
Severity High
Description

A denial of service vulnerability exists in Oracle TimesTen In-Memory Database service. The vulnerability is due to an input validation error while parsing HTTP GET requests. Remote unauthenticated attackers can exploit this vulnerability by sending a specially crafted HTTP request to the timestend daemon listening on port 17000/TCP.

Successful exploitation would cause the database service to terminate abnormally, resulting in the Denial of Service condition.

Affected Products
  • Oracle TimesTen In-Memory Database (7.0.5)
CVSS Score Base:
  • Access vector is NETWORK
  • Access complexity is LOW
  • Level of authentication required is NONE
  • Impact of this vulnerability on data confidentiality is NONE
  • Impact of this vulnerability on data integrity is NONE
  • Impact of this vulnerability on data availability is COMPLETE
Temporal:
  • The exploitability level of this vulnerability is PROOF OF CONCEPT
  • The remediation level of this vulnerability is UNAVAILABLE
  • The report confidence level of this vulnerability is UNCORROBORATED