Oracle Data Quality PostcardPreviewInt onclose Remote Code Execution VulnerabilityZDI-14-109: April 21st, 2014
TippingPoint™ IPS Customer ProtectionTippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID 13219. For further product information on the TippingPoint IPS:
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Oracle Data Quality. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Vendor ResponseOracle has issued an update to correct this vulnerability. More details can be found at:
2013-07-23 - Vulnerability reported to vendor
2014-04-21 - Coordinated public release of advisory
CreditThis vulnerability was discovered by:
Andrea Micalizzi aka rgod