exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

NGSoracle.txt

NGSoracle.txt
Posted Nov 6, 2003
Authored by David Litchfield | Site ngssoftware.com

NGSSoftware Insight Security Research Advisory #NISR05112003 - Multiple Oracle Application Server SQL injection vulnerabilities exist for all OS platforms with Oracle 9i Application Server Release 1 and 2 and RDBMS.

tags | advisory, vulnerability, sql injection
SHA-256 | c14bf67a31522701aa71637b6fe672b5b213d2b13fe5d981c029e99e1d4ae4cf

NGSoracle.txt

Change Mirror Download
NGSSoftware Insight Security Research Advisory

Name : Multiple Oracle Application Server SQL Injection Vulnerabilities
Systems Affected: All OS platforms; Oracle9i Application Server Release 1
and 2 and RDBMS
Severity : High Risk
Vendor URL : http://www.oracle.com/
Author : David Litchfield (david@ngssoftware.com)
Date : 5th November 2003
Advisory number : #NISR05112003

Description
***********
Oracle's RDBMS, a leading database server package, supports stored packages
and procedures through the use of PL/SQL. These packages and procedures can
be accessed through Oracle's Application Server's Portal module. Oracle
Application Server is a web server designed for Oracle applications. Many of
the PL/SQL packages and procedures are vulnerable to SQL Injection. Using
these vulnerabilities an unauthenticated attacker can gain access to all
data in the database from the Internet.

Details
*******
By default, Oracle Application Server allows unauthenticated users on the
web to access PL/SQL packages and procedures stored in the RDBMS. When a
PL/SQL procedure is executed it either does so with the security rights of
the invoker or the definer. In the latter case, if a PL/SQL procedure
defined by the powerful 'SYS' or 'SYSTEM' login is executed by a low
privileged user that user can access data they would not directly be able to
access. By executing such a procedure via Oracle Application Server and with
these SQL Injection vulnerabilities it is possible for an attacker to gain
access to all data within the database. For example, an attacker could gain
access to account details including database usernames and password hashes.
Whilst there are some vulnerable packages that do allow this level of access
most do not. Those known to be vulnerable include the packages used for
Portal DB Forms, Hierarchy, XML Components and List of Values. All of the
packages are required by the RDBMS so they can't be deleted.


Fix Information
***************
NGSSoftware alerted Oracle to these vulnerabilities between September and
October 2002, last year. Oracle has reviewed the code of the PL/SQL Packages
and procedures and fixed these issues. A patch is available from Metalink.
Please see

http://otn.oracle.com/deploy/security/pdf/2003alert61.pdf

for more details.

NGSSoftware advise Oracle database customers to review and install the patch
as a matter of urgency.

A check for this issue already exists in NGSSQuirreL for Oracle, a
comprehensive automated vulnerability assessment tool for Oracle Database
Servers of which more information is available from the NGSSite.

http://www.ngssoftware.com/software/squirrelfororacle.html


About NGSSoftware
*****************
NGSSoftware design, research and develop intelligent, advanced application
security assessment scanners. Based in the United Kingdom, NGSSoftware have
offices in the South of London and the East Coast of Scotland. NGSSoftware's
sister company NGSConsulting, offers best of breed security consulting
services, specialising in application, host and network security
assessments.

http://www.ngssoftware.com/
http://www.ngsconsulting.com/

Telephone +44 208 401 0070
Fax +44 208 401 0076

enquiries@ngssoftware.com


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close