Vulnerability Name:

CVE-2006-3698 (CCN-27888)

Assigned:2006-07-18
Published:2006-07-18
Updated:2018-10-18
Summary:Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API.
Note: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB01 is related to multiple SQL injection vulnerabilities in SYS.DBMS_CDC_IMPDP using the (a) IMPORT_CHANGE_SET, (b) IMPORT_CHANGE_TABLE, (c) IMPORT_CHANGE_COLUMN, (d) IMPORT_SUBSCRIBER, (e) IMPORT_SUBSCRIBED_TABLE, (f) IMPORT_SUBSCRIBED_COLUMN, (g) VALIDATE_IMPORT, (h) VALIDATE_CHANGE_SET, (i) VALIDATE_CHANGE_TABLE, and (j) VALIDATE_SUBSCRIPTION procedures, and that DB03 is for SQL injection in the MAIN procedure for SYS.KUPW$WORKER.
CVSS v3 Severity:5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.3 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Authentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
5.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): 
Access Complexity (AC): 
Athentication (Au): 
Impact Metrics:Confidentiality (C): 
Integrity (I): 
Availibility (A): 
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Informational
References:Source: CCN
Type: Full-Disclosure Mailing List, Tue Jul 18 2006 - 16:42:57 CDT
Oracle Database - SQL Injection in SYS.KUPW$WORKER [DB03]

Source: MITRE
Type: CNA
CVE-2006-3698

Source: FULLDISC
Type: UNKNOWN
20060718 Oracle Database - SQL Injection in SYS.KUPW$WORKER [DB03]

Source: CCN
Type: SA21111
Oracle Products Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
21111

Source: CCN
Type: SA21165
HP Oracle for OpenView Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
21165

Source: CCN
Type: SECTRACK ID: 1016529
Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact

Source: SECTRACK
Type: UNKNOWN
1016529

Source: CCN
Type: Oracle Web site
Oracle Critical Patch Update Advisory - July 2006

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpujul2006-101315.html

Source: MISC
Type: Patch, Vendor Advisory
http://www.red-database-security.com/advisory/oracle_cpu_july_2006.html

Source: CCN
Type: Red-Database-Security Web site
Details Oracle Critical Patch Update July 2006 - V1.02

Source: MISC
Type: UNKNOWN
http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_cdc_impdp.html

Source: MISC
Type: UNKNOWN
http://www.red-database-security.com/advisory/oracle_sql_injection_kupw$worker.html

Source: BUGTRAQ
Type: UNKNOWN
20060718 Oracle Database - SQL Injection in SYS.KUPW$WORKER [DB03]

Source: BUGTRAQ
Type: UNKNOWN
20060718 Oracle Database - SQL Injection in SYS.DBMS_CDC_IMPDP [DB01]

Source: HP
Type: UNKNOWN
HPSBMA02133

Source: BID
Type: Patch
19054

Source: CCN
Type: BID-19054
Oracle July 2006 Security Update Multiple Vulnerabilities

Source: CCN
Type: US-CERT Technical Cyber Security Alert TA06-200A
Oracle Products Contain Multiple Vulnerabilities

Source: CERT
Type: US Government Resource
TA06-200A

Source: VUPEN
Type: Vendor Advisory
ADV-2006-2863

Source: VUPEN
Type: Vendor Advisory
ADV-2006-2947

Source: XF
Type: UNKNOWN
oracle-kupwworker-sql-injection(27888)

Source: XF
Type: UNKNOWN
oracle-kupwworker-sql-injection(27888)

Source: XF
Type: UNKNOWN
oracle-dbmscdcimpdp-sql-injection(27889)

Source: XF
Type: UNKNOWN
oracle-cpu-july-2006(27897)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:database_server:10.1.0.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Vulnerability Name:

    CVE-2006-3698 (CCN-27889)

    Assigned:2006-07-18
    Published:2006-07-18
    Updated:2006-07-18
    Summary:Oracle Database 10g is vulnerable to SQL injection in the SYS.DBMS_CDC_IMPDP package (Change Data Capture (CDC) component). A remote attacker with EXECUTE permissions could send specially-crafted SQL statements to the IMPORT_CHANGE_SET, IMPORT_CHANGE_TABLE, IMPORT_CHANGE_COLUMN, IMPORT_SUBSCRIBER, IMPORT_SUBSCRIBED_TABLE, IMPORT_SUBSCRIBED_COLUMN, VALIDATE_IMPORT, VALIDATE_CHANGE_SET, VALIDATE_CHANGE_TABLE or VALIDATE_SUBSCRIPTION procedure, which could allow the attacker to view, add, modify, or delete information in the back-end database.
    CVSS v3 Severity:5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
    Exploitability Metrics:Attack Vector (AV): Network
    Attack Complexity (AC): Low
    Privileges Required (PR): Low
    User Interaction (UI): Required
    Scope:Scope (S): Unchanged
    Impact Metrics:Confidentiality (C): Low
    Integrity (I): Low
    Availibility (A): Low
    CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
    8.7 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Authentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
    5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
    Exploitability Metrics:Access Vector (AV): 
    Access Complexity (AC): 
    Athentication (Au): 
    Impact Metrics:Confidentiality (C): 
    Integrity (I): 
    Availibility (A): 
    Vulnerability Consequences:Data Manipulation
    References:Source: CCN
    Type: BugTraq Mailing List, Tue Jul 18 2006 - 16:12:16 CDT
    Oracle Database - SQL Injection in SYS.DBMS_CDC_IMPDP [DB01]

    Source: MITRE
    Type: CNA
    CVE-2006-3698

    Source: CCN
    Type: SA21111
    Oracle Products Multiple Vulnerabilities

    Source: CCN
    Type: SA21165
    HP Oracle for OpenView Multiple Vulnerabilities

    Source: CCN
    Type: SECTRACK ID: 1016529
    Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact

    Source: CCN
    Type: Oracle Web site
    Oracle Critical Patch Update Advisory - July 2006

    Source: CCN
    Type: Red-Database-Security Web site
    Details Oracle Critical Patch Update July 2006 - V1.02

    Source: CCN
    Type: BID-19054
    Oracle July 2006 Security Update Multiple Vulnerabilities

    Source: CCN
    Type: US-CERT Technical Cyber Security Alert TA06-200A
    Oracle Products Contain Multiple Vulnerabilities

    Source: XF
    Type: UNKNOWN
    oracle-dbmscdcimpdp-sql-injection(27889)

    Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    oracle database server 10.1.0.5
    oracle database server 10.1.0.3 r1
    oracle database server 10.1.0.4 r1
    oracle database server 10.1.0.5 r1