what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 18621

Secunia Security Advisory 18621
Posted Jan 27, 2006
Authored by Secunia | Site secunia.com

Secunia Security Advisory - David Litchfield has reported a vulnerability in various Oracle products, which can be exploited by malicious people to bypass certain security restrictions.

tags | advisory
SHA-256 | a6a0d947804f8b6036d49cbd8591316f5773891e2894ebe9da49378e4d8f1c38

Secunia Security Advisory 18621

Change Mirror Download


TITLE:
Oracle Products PL/SQL Gateway Security Bypass Vulnerability

SECUNIA ADVISORY ID:
SA18621

VERIFY ADVISORY:
http://secunia.com/advisories/18621/

CRITICAL:
Highly critical

IMPACT:
Security Bypass

WHERE:
>From remote

SOFTWARE:
Oracle9i Database Standard Edition
http://secunia.com/product/358/
Oracle9i Database Enterprise Edition
http://secunia.com/product/359/
Oracle9i Application Server
http://secunia.com/product/443/
Oracle Application Server 10g
http://secunia.com/product/3190/
Oracle Database 8.x
http://secunia.com/product/360/
Oracle HTTP Server 8.x
http://secunia.com/product/2596/
Oracle HTTP Server 9.x
http://secunia.com/product/2597/

DESCRIPTION:
David Litchfield has reported a vulnerability in various Oracle
products, which can be exploited by malicious people to bypass
certain security restrictions.

The vulnerability is caused due to an error in the Oracle PL/SQL
Gateway component during the validation of certain HTTP requests.
This can be exploited to bypass the PLSQLExclusion list and gain
access to excluded packages and procedures via specially-crafted HTTP
requests.

Successful exploitation allows an attacker to gain DBA access to the
database server through the web server.

The vulnerability has been reported in the PL/SQL Gateway component
included in the Oracle Application Server and the Oracle HTTP
Server.

Note: The affected component may also be included in other Oracle
products.

SOLUTION:
Filter malicious characters and character sequences in a proxy or
firewall with URL filtering capabilities.

PROVIDED AND/OR DISCOVERED BY:
David Litchfield

ORIGINAL ADVISORY:
http://lists.grok.org.uk/pipermail/full-disclosure/2006-January/041742.html

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    0 Files
  • 17
    Apr 17th
    0 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close