|
|
>> Oracle Products Multiple Code Execution and Security Bypass Issues
|
Multiple vulnerabilities have been identified in various Oracle and BEA products, which could be exploited by remote or local attackers to cause a denial of service, read and manipulate certain data, disclose sensitive information, conduct SQL injection attacks, bypass security restrictions, or execute arbitrary commands.
These issues are caused by errors in the Advanced Queuing, Database Scheduler, Advanced Replication, Authentication, Oracle Database Vault, Oracle Spatial, Data Pump, Core RDBMS, Instance Management, Resource Manager, TimesTen Client/Server, Oracle HTTP Server, Oracle Portal, Oracle Internet Directory, Hyperion BI Plus, Mobile Application Server, Oracle Report Manager, Oracle iStore, Oracle Application Object Library, Oracle Applications Technology Stack, PeopleSoft PeopleTools, WebLogic Server Plugins and WebLogic Server components.
Affected Products
Oracle Database 11g version 11.1.0.6
Oracle Database 10g Release 2 version 10.2.0.2
Oracle Database 10g Release 2 version 10.2.0.3
Oracle Database 10g Release 2 version 10.2.0.4
Oracle Database 10g version 10.1.0.5
Oracle Database 9i Release 2 version 9.2.0.8
Oracle Database 9i Release 2 version 9.2.0.8DV
Oracle TimesTen In-Memory Database version 7.0.3.0.0
Oracle Application Server 10g Release 3 (10.1.3) version 10.1.3.1.0
Oracle Application Server 10g Release 3 (10.1.3) version 10.1.3.3.0
Oracle Application Server 10g Release 2 (10.1.2) version 10.1.2.2.0
Oracle Application Server 10g Release 2 (10.1.2) version 10.1.2.3.0
Oracle Application Server 10g (9.0.4) version 9.0.4.3
Oracle Hyperion BI Plus version 9.2.0.3
Oracle Hyperion BI Plus version 9.2.1.0
Oracle Hyperion BI Plus version 9.3.1.0
Oracle Hyperion Performance Suite version 8.3.2.4
Oracle Hyperion Performance Suite version 8.5.0.3
Oracle E-Business Suite Release 12 version 12.0.4
Oracle E-Business Suite Release 11i version 11.5.10.2
Oracle Enterprise Manager Database Control 11i version 11.1.0.6
Oracle Enterprise Manager Database Control 10g Release 2 version 10.2.0.2
Oracle Enterprise Manager Database Control 10g Release 2 version 10.2.0.3
Oracle Enterprise Manager Database Control 10g Release 2 version 10.2.0.4
Oracle Enterprise Manager Database Control 10g Release 1 version 10.1.0.5
Oracle Enterprise Manager Grid Control 10g Release 1 version 10.1.0.5
Oracle Enterprise Manager Grid Control 10g Release 1 version 10.1.0.6
Oracle PeopleSoft Enterprise PeopleTools version 8.48.17
Oracle PeopleSoft Enterprise PeopleTools version 8.49.11
Oracle PeopleSoft Enterprise CRM version 8.9
Oracle PeopleSoft Enterprise CRM version 9.0
Oracle WebLogic Server (formerly BEA WebLogic Server) version 10.0 through MP1
Oracle WebLogic Server (formerly BEA WebLogic Server) versions 9.0, 9.1, 9.2 through MP3
Oracle WebLogic Server (formerly BEA WebLogic Server) version 8.1 through SP6
Oracle WebLogic Server (formerly BEA WebLogic Server) version 7.0 through SP7
Oracle WebLogic Server (formerly BEA WebLogic Server) version 6.1 through SP7
Solution
Apply patches :
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html
References
http://www.vupen.com/english/advisories/2008/2109 http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html https://support.bea.com/application_content/product_portlets/securityadvisories/2792.html https://support.bea.com/application_content/product_portlets/securityadvisories/2791.html https://support.bea.com/application_content/product_portlets/securityadvisories/2786.html https://support.bea.com/application_content/product_portlets/securityadvisories/2785.html https://support.bea.com/application_content/product_portlets/securityadvisories/2789.html https://support.bea.com/application_content/product_portlets/securityadvisories/2790.html https://support.bea.com/application_content/product_portlets/securityadvisories/2782.html http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=725 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=726 http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=727
Credits
Vulnerabilities reported by Flavio Casetta (Yocoya), Esteban Martinez Fayo (Application Security, Inc.), Johannes Greil (SEC Consult), guyp (Sentrigo), Joxean Koret, Alexander Kornbrust (Red Database Security), Stephen Kost (Integrigy), Dave Lewis, David Litchfield (NGS Software), Hirofumi Oka (JPCERT/CC Vulnerability Handling Team), Tanel Poder, Alexandr Polyakov (Digital Security), Andrea Purificato, and Dave Wichers (Aspect Security).
ChangeLog
2008-07-16 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|