Vulnerability Name: CVE-2006-0276 (CCN-24321) Assigned: 2006-01-17 Published: 2006-01-17 Updated: 2017-07-20 Summary: Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Collaboration Suite Wireless & Voice (component; 12) OCS12 and (13) OCS13 in the (c) Oracle Content (Management SDK component; 14) OCS14 and (15) OCS15 in the (d) Oracle (Content Services component. CVSS v3 Severity: 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Informational References: Source: MITRE Type: CNACVE-2005-2371 Source: MITRE Type: CNACVE-2006-0257 Source: MITRE Type: CNACVE-2006-0258 Source: MITRE Type: CNACVE-2006-0259 Source: MITRE Type: CNACVE-2006-0260 Source: MITRE Type: CNACVE-2006-0261 Source: MITRE Type: CNACVE-2006-0262 Source: MITRE Type: CNACVE-2006-0263 Source: MITRE Type: CNACVE-2006-0265 Source: MITRE Type: CNACVE-2006-0266 Source: MITRE Type: CNACVE-2006-0267 Source: MITRE Type: CNACVE-2006-0268 Source: MITRE Type: CNACVE-2006-0269 Source: MITRE Type: CNACVE-2006-0270 Source: MITRE Type: CNACVE-2006-0271 Source: MITRE Type: CNACVE-2006-0272 Source: MITRE Type: CNACVE-2006-0273 Source: MITRE Type: CNACVE-2006-0274 Source: MITRE Type: CNACVE-2006-0275 Source: MITRE Type: CNACVE-2006-0276 Source: MITRE Type: CNACVE-2006-0277 Source: MITRE Type: CNACVE-2006-0278 Source: MITRE Type: CNACVE-2006-0279 Source: MITRE Type: CNACVE-2006-0280 Source: MITRE Type: CNACVE-2006-0281 Source: MITRE Type: CNACVE-2006-0282 Source: MITRE Type: CNACVE-2006-0283 Source: MITRE Type: CNACVE-2006-0284 Source: MITRE Type: CNACVE-2006-0285 Source: MITRE Type: CNACVE-2006-0286 Source: MITRE Type: CNACVE-2006-0287 Source: MITRE Type: CNACVE-2006-0288 Source: MITRE Type: CNACVE-2006-0289 Source: MITRE Type: CNACVE-2006-0290 Source: MITRE Type: CNACVE-2006-0291 Source: MITRE Type: CNACVE-2006-0548 Source: MITRE Type: CNACVE-2006-0549 Source: MITRE Type: CNACVE-2006-0550 Source: MITRE Type: CNACVE-2006-0551 Source: MITRE Type: CNACVE-2006-0552 Source: CCN Type: SA18493Oracle Products Multiple Vulnerabilities and Security Issues Source: SECUNIA Type: Vendor Advisory18493 Source: CCN Type: SA18608HP Oracle for Openview Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory18608 Source: CCN Type: SECTRACK ID: 1015499Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: Patch1015499 Source: CCN Type: US-CERT VU#150332Oracle Text SQL injection vulnerability Source: CCN Type: US-CERT VU#472148Oracle Reports arbitrary file writing vulnerability Source: CCN Type: US-CERT VU#545804Oracle products contain multiple vulnerabilities Source: CERT-VN Type: Third Party Advisory, US Government ResourceVU#545804 Source: CCN Type: US-CERT VU#629316Oracle Database SYS.DBMS_METADATA_UTIL package SQL injection vulnerability Source: CCN Type: US-CERT VU#857412Oracle Transparent Data Encryption master encryption key stored as plaintext Source: CCN Type: US-CERT VU#870172Oracle Database Net Listener vulnerability Source: CCN Type: US-CERT VU#891644Oracle Database XML Database SQL Injection vulnerability Source: CCN Type: US-CERT VU#925261Oracle Reports arbitrary file reading vulnerability Source: CCN Type: US-CERT VU#983340Oracle Database Data Pump Metadata API SQL injection vulnerability Source: CCN Type: US-CERT VU#999268Oracle Client Tools buffer overflow vulnerability Source: CCN Type: Oracle Web siteOracle Critical Patch Update Advisory - January 2006 Source: CONFIRM Type: UNKNOWNhttp://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html Source: CCN Type: OSVDB ID: 22541Oracle Database Connection Manager Trivial Remote DoS Source: CCN Type: OSVDB ID: 22543Oracle Database Data Pump Metadata API DBMS_METADATA_UTIL Multiple Procedure SQL Injection Source: CCN Type: OSVDB ID: 22544Oracle Database Data Pump Metadata API DBMS_DATAPUMP Multiple Procedure SQL Injection Source: CCN Type: OSVDB ID: 22546Oracle Database Net Foundation Layer Unspecified Remote Issue Source: CCN Type: OSVDB ID: 22547Oracle Database Net Listener Multiple Unspecified Remote Issues (DB09) Source: CCN Type: OSVDB ID: 22549Oracle Database Net Listener Multiple Unspecified Remote Issues (DB11) Source: CCN Type: OSVDB ID: 22550Oracle Database Network Communications (RPC) Unspecified Remote Issue (DB12) Source: CCN Type: OSVDB ID: 22551Oracle Database Network Communications (RPC) Unspecified Remote Issue (DB13) Source: CCN Type: OSVDB ID: 22553Oracle Database Text cxtsys.catsearch Unspecified SQL Issue Source: CCN Type: OSVDB ID: 22555Oracle Database Text CTXSYS.DRILOAD Multiple Procedure SQL Injection Source: CCN Type: OSVDB ID: 22556Oracle Database TNS Authentication Phase AUTH_ALTER_SESSION Attribute SQL Injection Source: CCN Type: OSVDB ID: 22557Oracle Database Query Optimizer sys.outln_pkg Unspecified SQL Issue Source: CCN Type: OSVDB ID: 22558Oracle Database Query Optimizer Unspecified Trivial Remote DoS Source: CCN Type: OSVDB ID: 22559Oracle Database Security sys.dbms_fga.add_policy Unspecified SQL Issue Source: CCN Type: OSVDB ID: 22563Oracle Database Streams Capture DBMS_CDC_PUBLISH SET_DIRECTORY_ROOT Procedure SQL Injection Source: CCN Type: OSVDB ID: 22566Oracle Database Upgrade & Downgrade DBMS_REGISTRY Multiple Procedure SQL Injection Source: CCN Type: OSVDB ID: 22568Oracle Protocol Support Unspecified Limited Impact Remote Issue Source: CCN Type: OSVDB ID: 22569Oracle Reorganize Objects & Convert Tablespace Unspecified Local Issue Source: CCN Type: OSVDB ID: 22570Oracle Java Net Network (OID) Unspecified Trivial Remote Information Disclosure Source: CCN Type: OSVDB ID: 22571Oracle Database HTTP Server Unspecified Trivial Remote Information Disclosure Source: CCN Type: OSVDB ID: 22572Oracle Database HTTP Server Unspecified Trivial Remote DoS Source: CCN Type: OSVDB ID: 22573Oracle Workflow Cartridge HTTP Unspecified Trivial Remote Information Disclosure (WF01) Source: CCN Type: OSVDB ID: 22574Oracle Workflow Cartridge HTTP Unspecified Trivial Remote Information Disclosure (WF02) Source: CCN Type: OSVDB ID: 22575Oracle Workflow Cartridge HTTP Unspecified Trivial Remote Information Disclosure (WF03) Source: CCN Type: OSVDB ID: 22576Oracle Application Server Portal HTTP Unspecified Trivial Remote Information Disclosure Source: CCN Type: OSVDB ID: 22577Oracle Forms HTTP Unspecified Remote Issue Source: CCN Type: OSVDB ID: 22578Oracle Forms File Upload Unspecified Issue Source: CCN Type: OSVDB ID: 22579Oracle Reports Developer HTTP Unspecified Remote Issue Source: CCN Type: OSVDB ID: 22580Oracle Application Server Reports Developer HTTP Unspecified Remote DoS Source: CCN Type: OSVDB ID: 22581Oracle Application Server Reports Developer File Upload Unspecified Issue Source: CCN Type: OSVDB ID: 22582Oracle Application Server Reports Developer rwservlet customize Variable Arbitrary XML File Portion Disclosure Source: CCN Type: OSVDB ID: 22585Oracle Collaboration Suite Email Server Trivial Remote Information Disclosure (OCS01) Source: CCN Type: OSVDB ID: 22586Oracle Collaboration Suite Email Server Trivial Remote Information Disclosure (OCS02) Source: CCN Type: OSVDB ID: 22587Oracle Collaboration Suite Email Server IMAP Authenticated Remote Trivial DoS Source: CCN Type: OSVDB ID: 22588Oracle Collaboration Suite Email Server IMAP/POP Unauthenticated Remote Trivial DoS Source: CCN Type: OSVDB ID: 22589Oracle Collaboration Suite Email Server SMTP Unspecified Issue (OCS05) Source: CCN Type: OSVDB ID: 22590Oracle Collaboration Suite Email Server SMTP Unspecified Issue (OCS06) Source: CCN Type: OSVDB ID: 22591Oracle Collaboration Suite Email Server SMTP Unspecified Issue (OCS07) Source: CCN Type: OSVDB ID: 22592Oracle Collaboration Suite Email Server Unspecified Local Trivial Information Disclosure Source: CCN Type: OSVDB ID: 22593Oracle Collaboration Suite Email Server HTTP Unspecified Remote Information Disclosure Source: CCN Type: OSVDB ID: 22594Oracle Collaboration Suite Wireless & Voice Local Information Disclosure Source: CCN Type: OSVDB ID: 22595Oracle Collaboration Suite Wireless & Voice Authenticated SMS Remote Information Disclosure Source: CCN Type: OSVDB ID: 22596Oracle Collaboration Suite Management SDK FTP Unspecified Issue Source: CCN Type: OSVDB ID: 22597Oracle Collaboration Suite Management SDK HTTP Unspecified Authenticated Issue Source: CCN Type: OSVDB ID: 22598Oracle Collaboration Suite Content Services Email Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 22599Oracle Collaboration Suite Content Services HTTP Unspecified Issue Source: CCN Type: OSVDB ID: 22600Oracle E-Business Suite/Applications Application Install Log File Local Information Disclosure Source: CCN Type: OSVDB ID: 22601Oracle E-Business Suite/Applications CRM Technical Foundation HTTP Information Disclosure Source: CCN Type: OSVDB ID: 22602Oracle E-Business Suite/Applications iProcurement HTTP Information Disclosure Source: CCN Type: OSVDB ID: 22603Oracle E-Business Suite/Applications Application Object Library Log File Information Disclosure Source: CCN Type: OSVDB ID: 22604Oracle E-Business Suite/Applications Application Object Library HTTP Information Disclosure (APPS05) Source: CCN Type: OSVDB ID: 22605Oracle E-Business Suite/Applications Application Object Library HTTP Information Disclosure (APPS06) Source: CCN Type: OSVDB ID: 22606Oracle E-Business Suite/Applications Applications Framework HTTP Unspecified Authenticated Issue Source: CCN Type: OSVDB ID: 22607Oracle E-Business Suite/Applications Applications Technology Stack HTTP Trivial Information Disclosure (APPS08) Source: CCN Type: OSVDB ID: 22608Oracle E-Business Suite/Applications Applications Technology Stack HTTP Trivial Information Disclosure (APPS10) Source: CCN Type: OSVDB ID: 22609Oracle E-Business Suite/Applications Applications Technology Stack HTTP Trivial Information Disclosure (APPS11) Source: CCN Type: OSVDB ID: 22610Oracle E-Business Suite/Applications Human Resources HTTP Authenticated Information Disclosure Source: CCN Type: OSVDB ID: 22611Oracle E-Business Suite/Applications iLearning HTTP Information Disclosure (APPS13) Source: CCN Type: OSVDB ID: 22612Oracle E-Business Suite/Applications iLearning HTTP Information Disclosure (APPS14) Source: CCN Type: OSVDB ID: 22613Oracle E-Business Suite/Applications Marketing HTTP Authenticated Issue (APPS15) Source: CCN Type: OSVDB ID: 22614Oracle E-Business Suite/Applications Marketing HTTP Authenticated Issue (APPS16) Source: CCN Type: OSVDB ID: 22615Oracle E-Business Suite/Applications Marketing Encyclopedia System HTTP Information Disclosure Source: CCN Type: OSVDB ID: 22616Oracle E-Business Suite/Applications Trade Management HTTP Information Disclosure Source: CCN Type: OSVDB ID: 22617Oracle E-Business Suite/Applications Web Applications Desktop Integration HTTP Information Disclosure Source: CCN Type: OSVDB ID: 22618Oracle PeopleSoft Enterprise Portal Unspecified Local Issue Source: CCN Type: OSVDB ID: 22619Oracle JD Edwards HTML Server HTTP Unspecified Issue Source: CCN Type: OSVDB ID: 22620Oracle E-Business Suite/Applications Applications Technology Stack HTTP Trivial Information Disclosure (APPS09) Source: CCN Type: OSVDB ID: 22637Oracle Database Data Pump Metadata API DBMS_METADATA_INT Multiple Procedure SQL Injection Source: CCN Type: OSVDB ID: 22639Oracle Database Text CTXSYS.DRIDML CLEAN_DML Procedure SQL Injection Source: CCN Type: OSVDB ID: 22640Oracle Database Text CTXSYS.CTX_DOC GET_ROWID Procedure SQL Injection Source: CCN Type: OSVDB ID: 22641Oracle Database Text CTXSYS.CTX_QUERY BROWSE_WORDS Procedure SQL Injection Source: CCN Type: OSVDB ID: 22642Oracle Database Text CATINDEXMETHODS Multiple Procedure SQL Injection Source: CCN Type: OSVDB ID: 22643Oracle Database Data Pump Metadata API DBMS_METADATA Unspecified Procedure SQL Injection Source: CCN Type: OSVDB ID: 60409Oracle Client Utility Unspecified Remote Overflow Source: BID Type: Exploit16287 Source: CCN Type: BID-16287Oracle January Security Update Multiple Vulnerabilities Source: VUPEN Type: Vendor AdvisoryADV-2006-0243 Source: VUPEN Type: Vendor AdvisoryADV-2006-0323 Source: CCN Type: IBM Internet Security Systems X-Force DatabaseOracle Reports Server customize parameter information disclosure Source: XF Type: UNKNOWNoracle-january2006-update(24321) Source: XF Type: UNKNOWNoracle-january2006-update(24321) Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:8.0.6.3:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.1.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.1.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.0:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:10.1.1:r1:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:10.1.2:r1:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_portal:8.4:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_portal:8.8:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_portal:8.9:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.4.2:r1:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:9.0.2.1:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:6i:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:10.1.2.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.1:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.2:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.3:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.4:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.5:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.6:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.7:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.8:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:* OR cpe:/a:oracle:workflow:11.5.1:*:*:*:*:*:*:* OR cpe:/a:oracle:workflow:11.5.9.5:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle collaboration suite 9.0.4.2 r2
oracle application server 1.0.2.2
oracle database server 9.2.0.6 r2
oracle database server 8.0.6.3
oracle database server 10.1.0.3 r1
oracle application server 9.0.4.1
oracle collaboration suite 9.0.4.2 r2
oracle database server 9.0.1.5
oracle database server 10.1.0.4 r1
oracle enterprise manager grid control 10.1.0.3
oracle developer suite 9.0.4.1
oracle application server 9.0.4.2
oracle enterprise manager grid control 10.1.0.4
oracle application server 10.1.2.0.0 r2
oracle application server 10.1.2.0.1 r2
oracle application server 10.1.2.0.2 r2
oracle database server 10.2.0.1 r2
oracle database server 10.1.0.5 r1
oracle database server 9.2.0.7 r2
oracle collaboration suite 10.1.1 r1
oracle collaboration suite 10.1.2 r1
oracle e-business suite 11.5.10
oracle peoplesoft enterprise portal 8.4
oracle peoplesoft enterprise portal 8.8
oracle peoplesoft enterprise portal 8.9
oracle database server 10.1.0.4.2 r1
oracle developer suite 9.0.2.1
oracle developer suite 6i
oracle developer suite 9.0.4.2
oracle developer suite 10.1.2.0.2
oracle e-business suite 11.5.1
oracle e-business suite 11.5.2
oracle e-business suite 11.5.3
oracle e-business suite 11.5.4
oracle e-business suite 11.5.5
oracle e-business suite 11.5.6
oracle e-business suite 11.5.7
oracle e-business suite 11.5.8
oracle e-business suite 11.5.9
oracle workflow 11.5.1
oracle workflow 11.5.9.5