what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 29829

Secunia Security Advisory 29829
Posted Apr 16, 2008
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Multiple vulnerabilities have been reported for various Oracle products. Some vulnerabilities have unknown impacts while others can be exploited by malicious users to bypass certain security restrictions, conduct SQL injection attacks, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.

tags | advisory, denial of service, vulnerability, sql injection
SHA-256 | c37bd3b2bb8d24aba55976dee3446b830d6040298ba5df01872fbab785b526fa

Secunia Security Advisory 29829

Change Mirror Download
----------------------------------------------------------------------

Secunia Network Software Inspector 2.0 (NSI) - Public Beta

15 days left of beta period.

The 1st generation of the Secunia Network Software Inspector (NSI)
has been available for corporate users for almost 1 year and its been
a tremendous success.

The 2nd generation Secunia NSI is built on the same technology as the
award winning Secunia PSI, which has already been downloaded and
installed on more than 400,000 computers world wide.

Learn more / Download (instant access):
http://secunia.com/network_software_inspector_2/

----------------------------------------------------------------------

TITLE:
Oracle Products Multiple Vulnerabilities

SECUNIA ADVISORY ID:
SA29829

VERIFY ADVISORY:
http://secunia.com/advisories/29829/

CRITICAL:
Highly critical

IMPACT:
Unknown, Security Bypass, Manipulation of data, DoS, System access

WHERE:
>From remote

SOFTWARE:
Oracle9i Database Standard Edition
http://secunia.com/product/358/
Oracle9i Database Enterprise Edition
http://secunia.com/product/359/
Oracle Siebel SimBuilder 7.x
http://secunia.com/product/17175/
Oracle PeopleSoft Enterprise Tools 8.x
http://secunia.com/product/9411/
Oracle PeopleSoft Enterprise Human Capital Management 9.x
http://secunia.com/product/14817/
Oracle PeopleSoft Enterprise Human Capital Management 8.x
http://secunia.com/product/13980/
Oracle E-Business Suite 12.x
http://secunia.com/product/13979/
Oracle E-Business Suite 11i
http://secunia.com/product/442/
Oracle Database 11.x
http://secunia.com/product/18050/
Oracle Database 10.x
http://secunia.com/product/3387/
Oracle Collaboration Suite 10.x
http://secunia.com/product/2450/
Oracle Application Server 10g
http://secunia.com/product/3190/
Oracle JInitiator 1.x
http://secunia.com/product/7515/

DESCRIPTION:
Multiple vulnerabilities have been reported for various Oracle
products. Some vulnerabilities have unknown impacts while others can
be exploited by malicious users to bypass certain security
restrictions, conduct SQL injection attacks, cause a DoS (Denial of
Service), or potentially compromise a vulnerable system.

1) Input passed via unspecified parameters to the SDO_GEOM, SDO_IDX,
and SDO_UTIL packages is not properly sanitised before being used in
SQL queries. This can be exploited to manipulate SQL queries by
injecting arbitrary SQL code.

2) The problem is that the DBMS_STATS_INTERNAL package resets the
OUTLN password to a default value and grants DBA privileges to the
OUTLN user during the creation of a materialized view.

The remaining vulnerabilities are caused due to unspecified errors.
No more information is currently available.

The vulnerabilities are reported in the following products and
versions:
* Oracle Database 11g, version 11.1.0.6
* Oracle Database 10g Release 2, versions 10.2.0.2, 10.2.0.3
* Oracle Database 10g, version 10.1.0.5
* Oracle Database 9i Release 2, versions 9.2.0.8, 9.2.0.8DV
* Oracle Application Server 10g Release 3 (10.1.3), versions
10.1.3.1.0, 10.1.3.3.0
* Oracle Application Server 10g Release 2 (10.1.2), versions
10.1.2.0.2, 10.1.2.1.0, 10.1.2.2.0
* Oracle Application Server 10g (9.0.4), version 9.0.4.3
* Oracle Collaboration Suite 10g, version 10.1.2
* Oracle E-Business Suite Release 12, version 12.0.4
* Oracle E-Business Suite Release 11i, version 11.5.10.2
* Oracle PeopleSoft Enterprise PeopleTools versions 8.22.19, 8.48.16,
8.49.09
* Oracle PeopleSoft Enterprise HCM versions 8.8 SP1, 8.9, 9.0
* Oracle Siebel SimBuilder versions 7.8.2, 7.8.5

SOLUTION:
Apply patches (see the vendor's advisory).

PROVIDED AND/OR DISCOVERED BY:
The vendor credits:
* Cesar Cerrudo of Argeniss
* Esteban Martinez Fayo of Application Security, Inc.
* Joxean Koret
* Alexander Kornbrust of Red Database Security
* Stephen Kost of Integrigy
* Ali Kumcu of inTellectPro
* Amichai Shulman of Imperva, Inc.
* Sumit Siddharth of Portcullis Computer Security Limited
* Paul M. Wright

ORIGINAL ADVISORY:
Oracle:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2008.html

Red Database Security:
http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_geom.html
http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_idx.html
http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_util.html
http://www.red-database-security.com/advisory/oracle_outln_password_change.html

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close