Vulnerability Name:

CVE-2008-2595 (CCN-43805)

Assigned:2008-07-15
Published:2008-07-15
Updated:2017-09-29
Summary:Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors.
Note: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2008-2595

Source: HP
Type: UNKNOWN
SSRT061201

Source: IDEFENSE
Type: UNKNOWN
20080715 Oracle Internet Directory Pre-Authentication LDAP DoS Vulnerability

Source: CCN
Type: Packetstorm Security Website
DM FileManager Remote File Inclusion

Source: CCN
Type: SA31087
Oracle Products Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
31087

Source: CCN
Type: SA31113
HP Oracle for OpenView Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
31113

Source: CCN
Type: SECTRACK ID: 1020494
Oracle Application Server Bugs Let Remote Users Access and Modify Data and Cause Denial of Service Conditions

Source: CCN
Type: Oracle Critical Patch Update - July 2008
Oracle Critical Patch Update Advisory - July 2008

Source: CONFIRM
Type: UNKNOWN
http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.html

Source: CCN
Type: BID-30177
Oracle July 2008 Critical Patch Update Multiple Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1020494

Source: VUPEN
Type: UNKNOWN
ADV-2008-2109

Source: VUPEN
Type: UNKNOWN
ADV-2008-2115

Source: XF
Type: UNKNOWN
oracle-appserv-internetdirectory-dos(43805)

Source: CCN
Type: iDefense Labs PUBLIC ADVISORY: 07.15.08
Oracle Internet Directory Pre-Authentication LDAP DoS Vulnerability

Source: EXPLOIT-DB
Type: UNKNOWN
6101

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:database_10g:10.1.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_10g:10.1.4.2:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:database_9i:9.0.4.3:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    oracle database 10g 10.1.2.3
    oracle database 10g 10.1.4.2
    oracle database 9i 9.0.4.3
    oracle application server 9.0.4.3