Secunia Logo  


Secunia PSI WorldMap
 
Oracle Products Multiple Vulnerabilities
Secunia Advisory: SA33525
Release Date: 2009-01-14
Last Update: 2009-02-03
Popularity: 6,433 views

Critical:
Highly critical
Impact: Unknown
Cross Site Scripting
Manipulation of data
Exposure of system information
Privilege escalation
DoS
System access
Where: From remote
Solution Status: Vendor Patch

Software:JD Edwards EnterpriseOne Tools 8.x
JD Edwards OneWorld Tools 8.x
Oracle Application Server 10g
Oracle Collaboration Suite 10.x
Oracle Database 10.x
Oracle Database 11.x
Oracle E-Business Suite 11i
Oracle E-Business Suite 12.x
Oracle Enterprise Manager 10.x
Oracle PeopleSoft Enterprise Human Resource Management System 8.x
Oracle PeopleSoft Enterprise Human Resource Management System 9.x
Oracle Secure Backup 10.x
Oracle Times-Ten In-Memory Database 7.x
Oracle9i Database Enterprise Edition
Oracle9i Database Standard Edition

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 2 of 3)[ 1 ] [ 2 ] [ 3 ]

Solution:
Apply the patches (see the vendor's advisory).

Provided and/or discovered by:
The vendor credits:
* Deniz Cevik, Intellect
* Andy Davis, Information Risk Management Plc (IRM Plc)
* Franz Huell, Red Database Security
* Wasim Iqbal
* Alexander Kornbrust, Red Database Security
* Sasa Kos, ACROS Security
* Andy Sch., Centre for the Protection of National Infrastructure
* Daiki Fukumori [Secure Sky Technology], JPCERT/CC Vulnerability Handling Team
* Geoff Whittington, Assurent Secure Technologies

1) Code Audit Labs, reported via iDefense
2, 3, 4) An anonymous person, reported via iDefense
5) David Litchfield, NGS Software
6) Alexandr Polyakov, Digital Security Reasearch Group
7, 8) Joxean Koret
9 - 11) Xiaopeng Zhang and Zhenhua Liu, Fortinet, Inc.
12) Aditya K. Sood, SecNiche Security
13, 14) Esteban Martinez Fayo, Application Security, Inc.

Changelog:
2009-01-14: Updated "Description" to include vulnerability #5 and #6.
2009-01-15: Added vulnerabilities #7 and #8. Updated credits section. Added links to "Original Advisory" section.
2009-01-16: Added vulnerabilities #9 - #11. Updated credits section. Added links to "Original Advisory" section.
2009-01-19: Added vulnerability #12 to advisory. Updated credits section. Added link to "Original Advisory" section.
2009-02-03: Added vulnerabilities #13 and #14 to the advisory. Updated credits section. Added links to "Original Advisory" section.

Original Advisory:
Oracle:
http://www.oracle.com/technology/depl...ritical-patch-updates/cpujan2009.html

iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=767
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=768
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=769

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-09-003/
http://www.zerodayinitiative.com/advisories/ZDI-09-004/

Joxean Koret:
http://joxeankoret.com/blog/?p=39
http://joxeankoret.com/blog/?p=41

Fortinet, Inc:
http://www.fortiguardcenter.com/advisory/FGA-2009-02.html

SecNiche Security:
http://www.secniche.org/orabs.html

Application Security, Inc:
http://www.appsecinc.com/resources/alerts/oracle/2009-02.shtml
http://www.appsecinc.com/resources/alerts/oracle/2009-01.shtml

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Red Hat update for kdelibs // 65 views
2. rPath update for sun-jdk and sun-jre // 55 views
3. Ubuntu update for libvorbis // 54 views
4. Symantec Altiris ConsoleUtilities ActiveX Control "RunCmd()" Buffer Overflow // 51 views
5. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 50 views
6. Internet Explorer Layout Handling Memory Corruption Vulnerability // 47 views
7. Sun Solaris sshd Timeout Mechanism Denial of Service // 47 views
8. ISC BIND DNSSEC Cache Poisoning Vulnerability // 46 views
9. rPath update for httpd and mod_ssl // 41 views
10. Firefox Yoono Extension Cross-Context Scripting Vulnerability // 40 views