Vulnerability Name: CVE-2006-0435 (CCN-24363) Assigned: 2006-01-25 Published: 2006-01-25 Updated: 2018-10-19 Summary: Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01. CVSS v3 Severity: 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Access References: Source: CCN Type: Full-Disclosure Mailing List, Wed Jan 25 2006 - 12:26:15 CSTWorkaround for unpatched Oracle PLSQL Gateway flaw Source: CCN Type: Full-Disclosure Mailing List, Thu Feb 02 2006 - 12:37:45 CSTThe History of the Oracle PLSQL Gateway Flaw Source: CCN Type: Full-Disclosure Mailing List, Thu Feb 02 2006 - 12:39:44 CSTMore on the workaround for the unpatched Oracle PLSQL Gateway flaw Source: MITRE Type: CNACVE-2006-0435 Source: FULLDISC Type: UNKNOWN20060202 The History of the Oracle PLSQL Gateway Flaw Source: FULLDISC Type: UNKNOWN20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw Source: FULLDISC Type: UNKNOWN20060125 Workaround for unpatched Oracle PLSQL Gateway flaw Source: CCN Type: SA18621Oracle Products PL/SQL Gateway Security Bypass Vulnerability Source: SECUNIA Type: UNKNOWN18621 Source: CCN Type: SA19712Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory19712 Source: CCN Type: SA19859HP Oracle for OpenView Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory19859 Source: SREASON Type: UNKNOWN402 Source: SREASON Type: UNKNOWN403 Source: CCN Type: SECTRACK ID: 1015544Oracle AS PLSQL Gateway PLSQLExclusion List Bug Lets Remote Users Gain Access to the Target Database Source: SECTRACK Type: UNKNOWN1015544 Source: CCN Type: SECTRACK ID: 1015961Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: Patch1015961 Source: CCN Type: US-CERT VU#169164Oracle PL/SQL Gateway fails to properly validate HTTP requests Source: CERT-VN Type: US Government ResourceVU#169164 Source: CCN Type: Oracle Web siteOracle Critical Patch Update Advisory - April 2006 Source: CONFIRM Type: UNKNOWNhttp://www.oracle.com/technetwork/topics/security/cpuapr2006-090826.html Source: MISC Type: UNKNOWNhttp://www.oracle.com/technology/deploy/security/pdf/public_vuln_to_advisory_mapping.html Source: OSVDB Type: UNKNOWN22719 Source: CCN Type: OSVDB ID: 22719Oracle Multiple Products PL/SQL Gateway PLSQLExclusion List Bypass Source: CCN Type: Red-Database-Security Web siteDetails Oracle Critical Patch Update April 2006 - V1.03 Source: BUGTRAQ Type: UNKNOWN20060125 Workaround for unpatched Oracle PLSQL Gateway flaw Source: BUGTRAQ Type: UNKNOWN20060131 Re: Workaround for unpatched Oracle PLSQL Gateway flaw Source: BUGTRAQ Type: UNKNOWN20060202 The History of the Oracle PLSQL Gateway Flaw Source: BUGTRAQ Type: UNKNOWN20060202 More on the workaround for the unpatched Oracle PLSQL Gateway flaw Source: BUGTRAQ Type: UNKNOWN20060208 Re: Workaround for unpatched Oracle PLSQL Gateway flaw Source: HP Type: UNKNOWNSSRT061148 Source: BID Type: UNKNOWN16384 Source: CCN Type: BID-16384Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability Source: VUPEN Type: Vendor AdvisoryADV-2006-0338 Source: VUPEN Type: Vendor AdvisoryADV-2006-1397 Source: VUPEN Type: Vendor AdvisoryADV-2006-1571 Source: XF Type: UNKNOWNoracle-plsql-command-execution(24363) Source: XF Type: UNKNOWNoracle-plsql-command-execution(24363) Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:application_server:*:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:1.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:1.0.2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:1.0.2.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:1.0.2.1s:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:1.0.2.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.2.0.0:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.2.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.2.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.2.3:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.3.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.0:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.2.0.6:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.2.0.7:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.0.3.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2_.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:1.0.2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:1.0.2.1:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:1.0.2.1s_for_apps:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:1.0.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:1.0.2.2_roll_up_2:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:8.1.7:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:9.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:9.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:9.0.2.3:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:9.0.3.1:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:9.1:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:9.2.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.1.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.1.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.0:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:10.1.1:r1:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:10.1.2:r1:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.2.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:enterpriseone:8.95:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.1:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.2:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.3:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.4:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.5:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.6:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.7:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.8:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:* OR cpe:/a:oracle:enterpriseone:8.95.f1:*:*:*:*:*:*:* OR cpe:/a:oracle:enterpriseone:8.95.j1:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_tools:8.46.12:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_tools:8.46:ga:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_tools:8.47.04:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_tools:8.47:ga:*:*:*:*:*:* OR cpe:/a:oracle:pharmaceutical:4.5.0:*:*:*:*:*:*:* OR cpe:/a:oracle:pharmaceutical:4.5.1:*:*:*:*:*:*:* OR cpe:/a:oracle:pharmaceutical:4.5.2:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle application server *
oracle application server 1.0.2
oracle application server 1.0.2.0
oracle application server 1.0.2.1
oracle application server 1.0.2.1s
oracle application server 1.0.2.2
oracle application server 1.0.2.2.2
oracle application server 9.0.2
oracle application server 9.0.2.0.0
oracle application server 9.0.2.0.1
oracle application server 9.0.2.1
oracle application server 9.0.2.2
oracle application server 9.0.2.3
oracle application server 9.0.3
oracle application server 9.0.3.1
oracle application server 9.0.4.0
oracle application server 9.0.4.1
oracle application server 9.0.4.2
oracle application server 9.2.0.6
oracle application server 9.2.0.7
oracle application server 10.1.0.2
oracle application server 10.1.0.3
oracle application server 10.1.0.3.1
oracle application server 10.1.0.4
oracle application server 10.1.2
oracle application server 10.1.2.0.2
oracle application server 10.1.2.1.0
oracle application server 10.1.2_.0.1
oracle http server 1.0.2.0
oracle http server 1.0.2.1
oracle http server 1.0.2.1s_for_apps
oracle http server 1.0.2.2
oracle http server 1.0.2.2_roll_up_2
oracle http server 8.1.7
oracle http server 9.0.1
oracle http server 9.0.2
oracle http server 9.0.2.3
oracle http server 9.0.3.1
oracle http server 9.1
oracle http server 9.2.0
oracle database server 8.1.7.4
oracle database server 9.2.0.6 r2
oracle application server 9.0.4.1
oracle collaboration suite 9.0.4.2 r2
oracle database server 10.1.0.4 r1
oracle e-business suite 11.0
oracle enterprise manager grid control 10.1.0.3
oracle application server 9.0.4.2
oracle enterprise manager grid control 10.1.0.4
oracle application server 10.1.2.0.0 r2
oracle application server 10.1.2.0.1 r2
oracle application server 10.1.2.0.2 r2
oracle database server 10.2.0.1 r2
oracle database server 10.1.0.5 r1
oracle database server 9.2.0.7 r2
oracle collaboration suite 10.1.1 r1
oracle collaboration suite 10.1.2 r1
oracle e-business suite 11.5.10
oracle database server 10.2.0.2 r2
oracle enterprise manager grid control 10.2.0.1
oracle enterpriseone 8.95
oracle e-business suite 11.5.1
oracle e-business suite 11.5.2
oracle e-business suite 11.5.3
oracle e-business suite 11.5.4
oracle e-business suite 11.5.5
oracle e-business suite 11.5.6
oracle e-business suite 11.5.7
oracle e-business suite 11.5.8
oracle e-business suite 11.5.9
oracle enterpriseone 8.95.f1
oracle enterpriseone 8.95.j1
oracle peoplesoft enterprise tools 8.46.12
oracle peoplesoft enterprise tools 8.46 ga
oracle peoplesoft enterprise tools 8.47.04
oracle peoplesoft enterprise tools 8.47 ga
oracle pharmaceutical 4.5.0
oracle pharmaceutical 4.5.1
oracle pharmaceutical 4.5.2