CERT-In Vulnerability Note
CIVN-2007-0158
Oracle Database Server Installation Security Bypass Vulnerability
Original Issue Date:December 14, 2007
Severity Rating: MEDIUM
Systems Affected
- Oracle Oracle11g Standard Edition One 11.1 6
- Oracle Oracle11g Standard and Enterprise Edition 11.1 6
- Oracle Oracle10g Standard Edition 10.2 .3,10.2 .2, 10.2 .1, 10.1 .5
- Oracle Oracle10g Standard Edition 10.1 .4.2, 10.1 .4
- Oracle Oracle10g Standard Edition 10.1 .0.5, 10.1 .0.4
- Oracle Oracle10g Standard Edition 10.1 .0.3.1, 10.1 .0.3, 10.1 .0.2
- Oracle Oracle10g Standard Edition 9.0.4 .0
- Oracle Oracle10g Standard Edition 10.2, 10.2 .3, 10.2 .2, 10.2 .1
- Oracle Oracle10g Personal Edition 10.1 .5, 10.1 .4,10.1 .0.4
- Oracle Oracle10g Personal Edition 10.1 .0.3.1, 10.1 .0.3, 10.1 .0.2
- Oracle Oracle10g Personal Edition 9.0.4 .0
- Oracle Oracle10g Personal Edition 10.2 ,10.2 .3, 10.2 .2,10.2 .1
- Oracle Oracle10g Enterprise Edition 10.1 .5
- Oracle Oracle10g Enterprise Edition 10.1 .4, 10.1 .0.4
- Oracle Oracle10g Enterprise Edition 10.1 .0.3.1, 10.1 .0.3
- Oracle Oracle10g Enterprise Edition 10.1 .0.2
- Oracle Oracle10g Enterprise Edition 9.0.4 .0
- Oracle Oracle10g Enterprise Edition 10.2
Overview
A Vulnerability is exists in various Oracle products, which could be exploited by malicious user locally or remotely to cause denial-of-service , conduct SQL injection and cross site scripting attacks or bypass certain security restrictions.
Description
This vulnerability exists in oracle products due to errors in the Installation Process of Oracle Products.
This vulnerability can be exploited by remote attacker via connecting to the listener by executing arbitrary code. After installing, an attacker using Database Configuration Assistant DBCA could access SYS or SYSTEM accounts and change the credentials of the User. Successful exploitation may result in disclosure of sensitive information, and denial-of-service conditions, conduct SQL injection and cross site scripting attacks or bypass certain security restrictions.
Solution
Apply Oracle Check List:
http://www.oracle.com/technology/deploy/security/pdf/twp_security_checklist_db_database_20071108.pdf
Vendor Information
Oracle Corporation
http://www.oracle.com/index.html
References
SecurityFocus
http://www.securityfocus.com/bid/26425/references
NVD
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6260
CVE Name
CVE-2007-6260
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|