Vulnerability Name: | CVE-2006-0257 (CCN-18965) | ||||||||
Assigned: | 2005-01-18 | ||||||||
Published: | 2005-01-18 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02. Note: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0256 Source: MITRE Type: CNA CVE-2006-0257 Source: CCN Type: SA18493 Oracle Products Multiple Vulnerabilities and Security Issues Source: SECUNIA Type: Vendor Advisory 18493 Source: CCN Type: SA18608 HP Oracle for Openview Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 18608 Source: CCN Type: SECTRACK ID: 1015499 Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: Patch, Vendor Advisory 1015499 Source: CCN Type: US-CERT VU#545804 Oracle products contain multiple vulnerabilities Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#545804 Source: CCN Type: Oracle Critical Patch Update Advisory January 2005 Critical Patch Update - January 2005 Source: CONFIRM Type: UNKNOWN http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html Source: OSVDB Type: UNKNOWN 22540 Source: CCN Type: OSVDB ID: 22539 Oracle Database Advanced Queuing sys.dbms_aqadm_sys* Unspecified SQL Issue Source: CCN Type: OSVDB ID: 22540 Oracle Database Change Data Capture DBMS_CDC_UTILITY Multiple Procedure SQL Injection Source: CCN Type: BID-12296 Oracle Database Multiple Unspecified Vulnerabilities Source: BID Type: Exploit 16287 Source: CCN Type: BID-16287 Oracle January Security Update Multiple Vulnerabilities Source: VUPEN Type: Vendor Advisory ADV-2006-0243 Source: VUPEN Type: Vendor Advisory ADV-2006-0323 Source: XF Type: UNKNOWN oracle-advancedqueuing-obtain-info(18965) Source: XF Type: UNKNOWN oracle-january2006-update(24321) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |