|
Oracle Products Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA24929
|
|
|
Release Date:
|
2007-04-18
|
|
Last Update:
|
2008-12-19
|
|
Popularity:
|
11,186 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Unknown Security Bypass Cross Site Scripting Manipulation of data Exposure of sensitive information Privilege escalation DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | JD Edwards EnterpriseOne Tools 8.x JD Edwards OneWorld Tools 8.x Oracle Application Server 10g Oracle Collaboration Suite 10.x Oracle Database 10.x Oracle E-Business Suite 11i Oracle E-Business Suite 12.x Oracle Enterprise Manager 9.x Oracle PeopleSoft Enterprise Human Capital Management 8.x Oracle PeopleSoft Enterprise Tools 8.x Oracle Secure Enterprise Search 10.x Oracle9i Database Enterprise Edition Oracle9i Database Standard Edition
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 2 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Solution: Apply patches (see the vendor's advisory).
Provided and/or discovered by: The vendor credits:
* Vicente Aguilera Diaz, Internet Security Auditors, S.L.
* Gerhard Eschelbeck, Qualys, Inc.
* Esteban Martinez Fayo, Application Security, Inc.
* Joxean Koret
* Alexander Kornbrust, Red Database Security GmbH
* David Litchfield and Paul M. Wright, NGSSoftware
* noderat ratty
* TippingPoint's Zero Day Initiative
Changelog: 2007-04-19: Added additional links. Updated "Description" section to add #5 through #12. Added CVE references and link to US-CERT.
2007-04-30: Added CVE reference.
2008-12-19: Added link to new ZDI advisory. Updated vulnerability #3 with additional information provided by ZDI.
Original Advisory: Oracle:
http://www.oracle.com/technology/depl...ritical-patch-updates/cpuapr2007.html
Red Database Security:
http://www.red-database-security.com/advisory/oracle_discoverer_servlet.html
http://www.red-database-security.com/advisory/oracle_css_ses.html
http://www.red-database-security.com/...cle_sql_injection_dbms_aqadm_sys.html
http://www.red-database-security.com/..._injection_dbms_upgrade_internal.html
http://www.red-database-security.com/advisory/bypass_oracle_logon_trigger.html
Application Security, Inc.:
http://www.appsecinc.com/resources/alerts/oracle/2007-07.shtml
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-07-016.html
http://www.zerodayinitiative.com/advisories/ZDI-07-017.html
http://www.zerodayinitiative.com/advisories/ZDI-08-088/
NGSSoftware:
http://www.ngssoftware.com/research/papers/NGSSoftware-OracleCPUAPR2007.pdf
Other References: SA24475:
http://secunia.com/advisories/24475
US-CERT VU#809457:
http://www.kb.cert.org/vuls/id/809457
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|