Vulnerability Name:

CVE-2006-5359 (CCN-30111)

Assigned:2006-10-17
Published:2006-10-17
Updated:2018-10-17
Summary:Multiple unspecified vulnerabilities in Oracle Reports Developer component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and Oracle E-Business Suite and Applications 11.5.10CU2, have unknown impact and remote attack vectors, aka Vuln# (1) REP01 and (2) REP02.
Note: as of 20061027, Oracle has not disputed reports from a reliable researcher that these issues are related to (a) showenv and (b) parsequery for REP01, and (c) cellwrapper and (d) delimiter for REP02.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
8.7 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N)
2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Informational
References:Source: CCN
Type: Full-Disclosure Mailing List, Mon Oct 23 2006 - 11:51:48 CDT
Various Cross-Site-Scripting Vulnerabilities in Oracle Reports

Source: MITRE
Type: CNA
CVE-2006-5359

Source: CCN
Type: SA22396
Oracle Products Multiple Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
22396

Source: CCN
Type: SECTRACK ID: 1017077
Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact

Source: SECTRACK
Type: UNKNOWN
1017077

Source: CCN
Type: Oracle Critical Patch Update - October 2006
Oracle Critical Patch Update Advisory - October 2006

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html

Source: CCN
Type: Red-Database-Security Web site
Details Oracle Critical Patch Update October 2006 - V1.02

Source: MISC
Type: UNKNOWN
http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html

Source: MISC
Type: UNKNOWN
http://www.red-database-security.com/advisory/oracle_reports_css.html

Source: BUGTRAQ
Type: UNKNOWN
20061023 Various Cross-Site-Scripting Vulnerabilities in Oracle Reports

Source: HP
Type: UNKNOWN
HPSBMA02133

Source: BID
Type: Patch
20588

Source: CCN
Type: BID-20588
Oracle October 2006 Security Update Multiple Vulnerabilities

Source: CERT
Type: US Government Resource
TA06-291A

Source: VUPEN
Type: Vendor Advisory
ADV-2006-4065

Source: XF
Type: UNKNOWN
oracle-reports-xss(30111)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:e-business_suite:11.5.10.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:*
  • OR cpe:/a:oracle:e-business_suite:11.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:developer_suite:9.0.4.1:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:10.1.2.0.0:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:10.1.2.0.1:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.2.0.1:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:collaboration_suite:10.1.2:r1:*:*:*:*:*:*
  • OR cpe:/a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_portal:8.8:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_portal:8.9:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:developer_suite:6i:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:developer_suite:9.0.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_server:10.2.0.2:r2:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:enterpriseone:8.95:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:enterpriseone:8.96:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.22:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:developer_suite:9.0.4.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:developer_suite:10.1.2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:developer_suite:10.1.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:apex:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:e-business_suite:11.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:e-business_suite:11.5.8:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:pharmaceutical:4.5.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:pharmaceutical:4.5.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    oracle application server 9.0.4.3
    oracle application server 10.1.2.0.2
    oracle e-business suite 11.5.10.2
    oracle application server 1.0.2.2
    oracle database server 8.1.7.4
    oracle database server 9.2.0.6 r2
    oracle database server 10.1.0.3 r1
    oracle application server 9.0.4.1
    oracle collaboration suite 9.0.4.2 r2
    oracle database server 9.0.1.5
    oracle database server 10.1.0.4 r1
    oracle e-business suite 11.0
    oracle developer suite 9.0.4.1
    oracle application server 9.0.4.2
    oracle application server 10.1.2.0.0 r2
    oracle application server 10.1.2.0.1 r2
    oracle application server 10.1.2.0.2 r2
    oracle database server 10.2.0.1 r2
    oracle database server 10.1.0.5 r1
    oracle database server 9.2.0.7 r2
    oracle collaboration suite 10.1.2 r1
    oracle e-business suite 11.5.10
    oracle peoplesoft enterprise portal 8.8
    oracle peoplesoft enterprise portal 8.9
    oracle developer suite 6i
    oracle developer suite 9.0.4.2
    oracle database server 10.2.0.2 r2
    oracle application server 9.0.4.3
    oracle enterpriseone 8.95
    oracle enterpriseone 8.96
    oracle peoplesoft enterprise peopletools 8.22
    oracle peoplesoft enterprise peopletools 8.47
    oracle peoplesoft enterprise peopletools 8.48
    oracle developer suite 9.0.4.3
    oracle developer suite 10.1.2.0.2
    oracle developer suite 10.1.2.2
    oracle apex 2.0
    oracle e-business suite 11.5.7
    oracle e-business suite 11.5.8
    oracle e-business suite 11.5.9
    oracle pharmaceutical 4.5.0
    oracle pharmaceutical 4.5.1