| Vulnerability Name: | CCN-20152 | ||||||
| Published: | 2005-04-18 | ||||||
| Updated: | 2005-04-18 | ||||||
| Summary: | Oracle Database Server is vulnerable to SQL injection. A remote attacker with EXECUTE privileges on the DBMS_CDC_IPUBLISH package could send specially-crafted SQL statements to the ALTER_MANUALLOG_CHANGE_SOURCE procedure using the CHANGE_SOURCE_NAME parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. | ||||||
| CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||
| CVSS v2 Severity: | 6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||
| Vulnerability Consequences: | Data Manipulation | ||||||
| References: | Source: CCN Type: SHATTER Team Security Alert April 18, 2005 SQL Injection in ALTER_MANUALLOG_CHANGE_SOURCE procedure Source: CCN Type: US-CERT VU#948486 Oracle products contain multiple vulnerabilities Source: CCN Type: Oracle Critical Patch Update Advisory April 2005 Oracle Critical Patch Update Advisory - April 2005 Source: CCN Type: BID-13139 Oracle Multiple Vulnerabilities Source: CCN Type: BID-13144 Oracle Database Multiple SQL Injection Vulnerabilities Source: CCN Type: BID-13235 Oracle Database Server ALTER_MANUALLOG_CHANGE_SOURCE SQL Injection Vulnerability Source: XF Type: UNKNOWN oracle-database-sql-injection(20152) | ||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
| BACK | |||||||