Vulnerability Name: | CVE-2005-1197 (CCN-20158) | ||||||||
Assigned: | 2005-04-18 | ||||||||
Published: | 2005-04-18 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 6.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-1197 Source: BUGTRAQ Type: UNKNOWN 20050418 [AppSecInc Team SHATTER Security Advisory] SQL Injection in CREATE_SCN_CHANGE_SET procedure Source: CCN Type: SHATTER Team Security Alert April 18, 2005 SQL Injection in CREATE_SCN_CHANGE_SET procedure Source: CCN Type: US-CERT VU#948486 Oracle products contain multiple vulnerabilities Source: CERT-VN Type: US Government Resource VU#948486 Source: CCN Type: Oracle Database Server Web page Oracle Database Source: CCN Type: Oracle Critical Patch Update Advisory April 2005 Oracle Critical Patch Update Advisory - April 2005 Source: CONFIRM Type: Patch, Vendor Advisory http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf Source: CCN Type: OSVDB ID: 15813 Oracle Database Server Change Data Capture DBMS_CDC_IPUBLISH CREATE_SCN_CHANGE_SET Procedure SQL Injection Source: CCN Type: BID-13139 Oracle Multiple Vulnerabilities Source: CCN Type: BID-13234 Oracle Database Server CREATE_SCN_CHANGE_SET Standard Procedure SQL Injection Vulnerability Source: CERT Type: US Government Resource TA05-117A Source: XF Type: UNKNOWN oracle-database-changesetname-sql-injection(20158) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |