Vulnerability Name:

CVE-2006-0257 (CCN-18965)

Assigned:2005-01-18
Published:2005-01-18
Updated:2017-07-20
Summary:Unspecified vulnerability in the Change Data Capture component of Oracle Database server 9.2.0.7, 10.1.0.5, and 10.2.0.1 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB02.
Note: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that the problem is SQL injection in the CDC_ALLOCATE_LOCK function of the DBMS_CDC_UTILITY package.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2006-0256

Source: MITRE
Type: CNA
CVE-2006-0257

Source: CCN
Type: SA18493
Oracle Products Multiple Vulnerabilities and Security Issues

Source: SECUNIA
Type: Vendor Advisory
18493

Source: CCN
Type: SA18608
HP Oracle for Openview Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
18608

Source: CCN
Type: SECTRACK ID: 1015499
Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact

Source: SECTRACK
Type: Patch, Vendor Advisory
1015499

Source: CCN
Type: US-CERT VU#545804
Oracle products contain multiple vulnerabilities

Source: CERT-VN
Type: Third Party Advisory, US Government Resource
VU#545804

Source: CCN
Type: Oracle Critical Patch Update Advisory January 2005
Critical Patch Update - January 2005

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html

Source: OSVDB
Type: UNKNOWN
22540

Source: CCN
Type: OSVDB ID: 22539
Oracle Database Advanced Queuing sys.dbms_aqadm_sys* Unspecified SQL Issue

Source: CCN
Type: OSVDB ID: 22540
Oracle Database Change Data Capture DBMS_CDC_UTILITY Multiple Procedure SQL Injection

Source: CCN
Type: BID-12296
Oracle Database Multiple Unspecified Vulnerabilities

Source: BID
Type: Exploit
16287

Source: CCN
Type: BID-16287
Oracle January Security Update Multiple Vulnerabilities

Source: VUPEN
Type: Vendor Advisory
ADV-2006-0243

Source: VUPEN
Type: Vendor Advisory
ADV-2006-0323

Source: XF
Type: UNKNOWN
oracle-advancedqueuing-obtain-info(18965)

Source: XF
Type: UNKNOWN
oracle-january2006-update(24321)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:database_server:9.2.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.2.0.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:database_server:8.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:9.0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:8.0.6.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:9.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    oracle database server 9.2.0.7
    oracle database server 10.1.0.5
    oracle database server 10.2.0.1
    oracle database server 8.0.6
    oracle application server 1.0.2.2
    oracle database server 8.1.7.4
    oracle application server 9.0.4.0
    oracle database server 9.2.0.6 r2
    oracle database server 8.0.6.3
    oracle database server 10.1.0.3 r1
    oracle application server 9.0.4
    oracle application server 9.0.4.1
    oracle collaboration suite 9.0.4.2 r2