HIGH
Unspecified vulnerability in Oracle Spatial component in Oracle Database 10.2.0.2 has unknown impact and remote authenticated attack vectors related to "create session" privileges, aka Vuln# DB02
Published Oct 18, 2006
7.1
HIGHCVSS 2.0
EPSS 2.46%
Description
Unspecified vulnerability in Oracle Spatial component in Oracle Database 10.2.0.2 has unknown impact and remote authenticated attack vectors related to "create session" privileges, aka Vuln# DB02. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB02 is for SQL injection in the SDO_DROP_USER_BEFORE package using a Trigger for a DROP USER statement in an anonymous PL/SQL block.
Affected products
No data.
- 10.2.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (10)
- http://secunia.com/advisories/22396 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1017077 vdb-entryx_refsource_SECTRACK
- http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf x_refsource_MISC
- http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html x_refsource_CONFIRM
- http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html x_refsource_MISC
- http://www.securityfocus.com/archive/1/449110/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/449711/100/0/threaded vendor-advisoryx_refsource_HP
- http://www.securityfocus.com/bid/20588 vdb-entryx_refsource_BIDPatch
- http://www.us-cert.gov/cas/techalerts/TA06-291A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/4065 vdb-entryx_refsource_VUPENVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/22396 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securitytracker.com/id?1017077 | vdb-entryx_refsource_SECTRACK | |
| http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf | x_refsource_MISC | |
| http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html | x_refsource_CONFIRM | |
| http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html | x_refsource_MISC | |
| http://www.securityfocus.com/archive/1/449110/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/449711/100/0/threaded | vendor-advisoryx_refsource_HP | |
| http://www.securityfocus.com/bid/20588 | vdb-entryx_refsource_BIDPatch | |
| http://www.us-cert.gov/cas/techalerts/TA06-291A.html | third-party-advisoryx_refsource_CERTUS Government Resource | |
| http://www.vupen.com/english/advisories/2006/4065 | vdb-entryx_refsource_VUPENVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 18, 2006
Updated Aug 7, 2024
Reserved Oct 17, 2006
Link CVE-2006-5333
CISA Vulnrichment
Updated n/a