|
|
|
>> Oracle Products Command Execution and SQL Injection Vulnerabilities
|
Multiple vulnerabilities have been identified in various Oracle products, which could be exploited by remote or local attackers to cause a denial of service, execute arbitrary commands, read and overwrite arbitrary data, disclose sensitive information, conduct SQL injection and cross site scripting attacks, or bypass security restrictions.
These issues are caused by errors in the Enterprise Manager, Advanced Queuing, Change Data Capture, Core RDBMS, Secure Enterprise Search or Ultrasearch, Spatial, Authentication, Net Services, Data Pump, Export, Query Optimizer, Audit, Application Express, Jinitiator, Dynamic Monitoring Service, Portal, Advanced Pricing, Application Object Library, Applications Framework, Applications Manager, Applications Technology Stack, PeopleTools, HCM Recruiting, HCM ePerformance, and SimBuilder components.
Affected Products
Oracle Database 11g version 11.1.0.6
Oracle Database 10g Release 2 version 10.2.0.2
Oracle Database 10g Release 2 version 10.2.0.3
Oracle Database 10g version 10.1.0.5
Oracle Database 9i Release 2 version 9.2.0.8
Oracle Database 9i Release 2 version 9.2.0.8DV
Oracle Database 9i version 9.0.1.5 FIPS+
Oracle Application Server 10g Release 3 (10.1.3) version 10.1.3.1.0
Oracle Application Server 10g Release 3 (10.1.3) version 10.1.3.3.0
Oracle Application Server 10g Release 2 (10.1.2) version 10.1.2.0.2
Oracle Application Server 10g Release 2 (10.1.2) version 10.1.2.1.0
Oracle Application Server 10g Release 2 (10.1.2) version 10.1.2.2.0
Oracle Application Server 10g (9.0.4) version 9.0.4.3
Oracle Application Server 9i Release 1 version 1.0.2.2
Oracle Collaboration Suite 10g version 10.1.2
Oracle E-Business Suite Release 12 version 12.0.4
Oracle E-Business Suite Release 11i version 11.5.10.2
Oracle PeopleSoft Enterprise PeopleTools version 8.22.19
Oracle PeopleSoft Enterprise PeopleTools version 8.48.16
Oracle PeopleSoft Enterprise PeopleTools version 8.49.09
Oracle PeopleSoft Enterprise HCM version 8.8 SP1
Oracle PeopleSoft Enterprise HCM version 8.9
Oracle PeopleSoft Enterprise HCM version 9.0
Oracle Siebel SimBuilder version 7.8.2
Oracle Siebel SimBuilder version 7.8.5
Solution
Apply patches :
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2008.html
References
http://www.vupen.com/english/advisories/2008/1233 http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2008.html http://www.red-database-security.com/advisory/oracle_outln_password_change.html http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_idx.html http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_geom.html http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_util.html
Credits
Vulnerabilities reported by Cesar Cerrudo (Argeniss), Esteban Martinez Fayo (Application Security, Inc.), Joxean Koret, iDefense Labs, Alexander Kornbrust (Red Database Security), Stephen Kost (Integrigy), Ali Kumcu (inTellectPro), Amichai Shulman (Imperva, Inc.), Sumit Siddharth (Portcullis Computer Security Limited) and Paul M. Wright (NGS Software).
ChangeLog
2008-04-16 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts with CVE, CWE, and CVSS when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |

|