CERT-In Advisory
CIAD-2005-0016
Multiple Vulnerabilities in Oracle Database
Original Issue Date: July 19, 2005
Severity Rating: High
Systems Affected
- Oracle Express Server,
- Oracle OLAP,
- Component Registry,
- CORE,
- XML Database,
- iSQL*Plus, Single Sign-on,
- Oracle HTTP Server
- Oracle EBusiness Suite Release 11i, 11.5.1 through 11.5.8Release 11.5.9 and later releases are not affected.
- Oracle Applications 11.0, All Releases
- Oracle Application Server
- Oracle Collaboration Suite
- Oracle E-Business and Applications,
- Oracle Enterprise Manager products
Overview
Multiple vulnerabilities have been reported in Oracle Database. These vulnerabilities could allow an attacker to gain access to or modify the database.
Description
Specific details of these vulnerabilities are not available. For more information regarding these vulnerabilities and the patches to correct them, refer to the Oracle Critical Patch Update for July 2005. The criticality of these vulnerabilities varies depending upon affected components and access privileges required.
If the attacker got required authentication these vulnerabilities may allow the attacker to cause Denial of Service conditions or gain access to the database. These vulnerabilities may have "wide impact" on the confidentiality, integrity, and availability of the target database and system.
Solution
Apply appropriate patches as suggested by vendor. Oracle
http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html
Vendor Information
Oracle
http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html
References
SecurityTracker Alert ID: 1014466
http://securitytracker.com/id?1014466
US-CERT Technical Cyber Security Alert TA05-194A
http://www.us-cert.gov/cas/techalerts/TA05-194A.html
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|