|
Oracle Products Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA33525
|
|
|
Release Date:
|
2009-01-14
|
|
Last Update:
|
2009-02-03
|
|
Popularity:
|
6,433 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Unknown Cross Site Scripting Manipulation of data Exposure of system information Privilege escalation DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | JD Edwards EnterpriseOne Tools 8.x JD Edwards OneWorld Tools 8.x Oracle Application Server 10g Oracle Collaboration Suite 10.x Oracle Database 10.x Oracle Database 11.x Oracle E-Business Suite 11i Oracle E-Business Suite 12.x Oracle Enterprise Manager 10.x Oracle PeopleSoft Enterprise Human Resource Management System 8.x Oracle PeopleSoft Enterprise Human Resource Management System 9.x Oracle Secure Backup 10.x Oracle Times-Ten In-Memory Database 7.x Oracle9i Database Enterprise Edition Oracle9i Database Standard Edition
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 2 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Solution: Apply the patches (see the vendor's advisory).
Provided and/or discovered by: The vendor credits:
* Deniz Cevik, Intellect
* Andy Davis, Information Risk Management Plc (IRM Plc)
* Franz Huell, Red Database Security
* Wasim Iqbal
* Alexander Kornbrust, Red Database Security
* Sasa Kos, ACROS Security
* Andy Sch., Centre for the Protection of National Infrastructure
* Daiki Fukumori [Secure Sky Technology], JPCERT/CC Vulnerability Handling Team
* Geoff Whittington, Assurent Secure Technologies
1) Code Audit Labs, reported via iDefense
2, 3, 4) An anonymous person, reported via iDefense
5) David Litchfield, NGS Software
6) Alexandr Polyakov, Digital Security Reasearch Group
7, 8) Joxean Koret
9 - 11) Xiaopeng Zhang and Zhenhua Liu, Fortinet, Inc.
12) Aditya K. Sood, SecNiche Security
13, 14) Esteban Martinez Fayo, Application Security, Inc.
Changelog: 2009-01-14: Updated "Description" to include vulnerability #5 and #6.
2009-01-15: Added vulnerabilities #7 and #8. Updated credits section. Added links to "Original Advisory" section.
2009-01-16: Added vulnerabilities #9 - #11. Updated credits section. Added links to "Original Advisory" section.
2009-01-19: Added vulnerability #12 to advisory. Updated credits section. Added link to "Original Advisory" section.
2009-02-03: Added vulnerabilities #13 and #14 to the advisory. Updated credits section. Added links to "Original Advisory" section.
Original Advisory: Oracle:
http://www.oracle.com/technology/depl...ritical-patch-updates/cpujan2009.html
iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=767
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=768
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=769
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-09-003/
http://www.zerodayinitiative.com/advisories/ZDI-09-004/
Joxean Koret:
http://joxeankoret.com/blog/?p=39
http://joxeankoret.com/blog/?p=41
Fortinet, Inc:
http://www.fortiguardcenter.com/advisory/FGA-2009-02.html
SecNiche Security:
http://www.secniche.org/orabs.html
Application Security, Inc:
http://www.appsecinc.com/resources/alerts/oracle/2009-02.shtml
http://www.appsecinc.com/resources/alerts/oracle/2009-01.shtml
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
Today
|
New advisories:
|
11 |
|
New vulnerabilities:
|
16 |
|
Updated advisories:
|
15 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|