|
Oracle Products Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA29829
|
|
|
Release Date:
|
2008-04-16
|
|
Last Update:
|
2008-04-30
|
|
Popularity:
|
10,130 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Unknown Security Bypass Manipulation of data DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Oracle Application Server 10g Oracle Collaboration Suite 10.x Oracle Database 10.x Oracle Database 11.x Oracle E-Business Suite 11i Oracle E-Business Suite 12.x Oracle JInitiator 1.x Oracle PeopleSoft Enterprise Human Capital Management 8.x Oracle PeopleSoft Enterprise Human Capital Management 9.x Oracle PeopleSoft Enterprise Tools 8.x Oracle Siebel SimBuilder 7.x Oracle9i Database Enterprise Edition Oracle9i Database Standard Edition
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 2 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Solution: Apply patches (see the vendor's advisory).
Provided and/or discovered by: The vendor credits:
* Cesar Cerrudo of Argeniss
* Esteban Martinez Fayo of Application Security, Inc.
* Joxean Koret
* Alexander Kornbrust of Red Database Security
* Stephen Kost of Integrigy
* Ali Kumcu of inTellectPro
* Amichai Shulman of Imperva, Inc.
* Sumit Siddharth of Portcullis Computer Security Limited
* Paul M. Wright
Changelog: 2008-04-17: Updated advisory with more information about vulnerability #3. Added CVE reference and updated the "Original Advisory" section.
2008-04-17: Added CVE reference.
2008-04-21: Updated advisory with more information about vulnerability #4. Updated "Original Advisory" section.
2008-04-24: Updated advisory with more information about vulnerability #5. Updated "Original Advisory" section.
2008-04-30: Updated advisory with more information about vulnerabilities #6, #7, and #8. Updated "Original Advisory" section.
Original Advisory: Oracle:
http://www.oracle.com/technology/depl...ritical-patch-updates/cpuapr2008.html
Red Database Security:
http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_geom.html
http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_idx.html
http://www.red-database-security.com/advisory/oracle_sql_injection_sdo_util.html
http://www.red-database-security.com/advisory/oracle_outln_password_change.html
iDefense:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=690
Imperva:
http://www.imperva.com/resources/adc/adc_advisories_oracle-dbms-04172008.html
Sumit Siddharth:
http://www.notsosecure.com/folder2/20...le-10g-express-edition-cookies-issue/
Application Security, Inc.:
http://www.appsecinc.com/resources/alerts/oracle/2008-01.shtml
http://www.appsecinc.com/resources/alerts/oracle/2008-02.shtml
http://www.appsecinc.com/resources/alerts/oracle/2008-03.shtml
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|