Description
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is for a buffer overflow.
Affected products
- oracle / apex1.5.0 – 1.5.0
- oracle / apex1.6.1 – 1.6.1
- oracle / apex2.0 – 2.0
- oracle / apex2.2 – 2.2
- oracle / application_server1.0.2.2 – 1.0.2.2
- oracle / application_server9.0.4.3 – 9.0.4.3
- oracle / application_server10.1.2.0.1 – 10.1.2.0.1
- oracle / application_server10.1.2.0.2 – 10.1.2.0.2
- oracle / application_server10.1.2.1.0 – 10.1.2.1.0
- oracle / application_server10.1.2.2.0 – 10.1.2.2.0
- oracle / application_server10.1.3.0.0 – 10.1.3.0.0
- oracle / application_server10.1.3.1.0 – 10.1.3.1.0
- oracle / application_server10.1.3.2.0 – 10.1.3.2.0
- oracle / application_server10.1.3.3.0 – 10.1.3.3.0
- oracle / collaboration_suite10.1.2 – 10.1.2
- oracle / database_server9.0.1.5 – 9.0.1.5
- oracle / database_server9.2.0.7 – 9.2.0.7
- oracle / database_server9.2.0.8 – 9.2.0.8
- oracle / database_server9.2.0.8dv – 9.2.0.8dv
- oracle / database_server10.1.0.5 – 10.1.0.5
- oracle / database_server10.2.0.2 – 10.2.0.2
- oracle / database_server10.2.0.3 – 10.2.0.3
- oracle / e-business_suite11.5.8 – 11.5.8
- oracle / e-business_suite11.5.9 – 11.5.9
- oracle / e-business_suite11.5.10 – 11.5.10
- oracle / e-business_suite11.5.10.2 – 11.5.10.2
- oracle / e-business_suite12.0.0 – 12.0.0
- oracle / e-business_suite12.0.1 – 12.0.1
- oracle / peoplesoft_enterprise_customer_relationship_management8.9 – 8.9
- oracle / peoplesoft_enterprise_customer_relationship_management9.0 – 9.0
- oracle / peoplesoft_enterprise_human_capital_management8.9 – 8.9
- oracle / peoplesoft_enterprise_human_capital_management9.0 – 9.0
- oracle / peoplesoft_enterprise_peopletools8.22 – 8.22
- oracle / peoplesoft_enterprise_peopletools8.47 – 8.47
- oracle / peoplesoft_enterprise_peopletools8.48 – 8.48
- oracle / peoplesoft_enterprise_peopletools8.49 – 8.49
- oracle / secure_enterprise_search10.1.6 – 10.1.6
- oracle / secure_enterprise_search10.1.8 – 10.1.8
References
- MISChttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143
- VENDOR_ADVISORYhttp://secunia.com/advisories/26114
- MISChttp://www.red-database-security.com/advisory/oracle_sql_injection_dbms_prvtaqis.html
- VENDOR_ADVISORYhttp://secunia.com/advisories/26166
- VENDOR_ADVISORYhttp://www.oracle.com/technetwork/topics/security/cpujul2007-087014.html
- MISChttp://www.us-cert.gov/cas/techalerts/TA07-200A.html
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/2562
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2007/2635
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/35497
- MISChttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/35490
- MISChttp://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdf
- MISChttp://www.securitytracker.com/id?1018415
- MISChttp://www.red-database-security.com/advisory/oracle_cpu_jul_2007.html