HIGH
Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (Vuln# DB05) and (2) sys.dbms_cdc_isubscribe (DB06)
Published Oct 18, 2006
9.0
HIGHCVSS 2.0
EPSS 3.33%
Description
Multiple unspecified vulnerabilities in the Change Data Capture (CDC) component in Oracle Database 9.2.0.7, 10.1.0.5, and have unknown impact and remote authenticated attack vectors related to (1) sys.dbms_cdc_ipublish (Vuln# DB05) and (2) sys.dbms_cdc_isubscribe (DB06). NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB05 is for SQL injection in CREATE_CHANGE_TABLE and CHANGE_TABLE_TRIGGER, and DB06 is for PL/SQL injection in the PREPARE_UNBOUNDED_VIEW procedure.
Affected products
No data.
OR
- 9.2.0.7
- 10.1.0.5
- 10.2.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (12)
- http://secunia.com/advisories/22396 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1017077 vdb-entryx_refsource_SECTRACK
- http://www.databasesecurity.com/oracle/OracleOct2006-CPU-Analysis.pdf x_refsource_MISC
- http://www.kb.cert.org/vuls/id/446100 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.kb.cert.org/vuls/id/716964 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html x_refsource_CONFIRM
- http://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html x_refsource_MISC
- http://www.securityfocus.com/archive/1/449110/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/449711/100/0/threaded vendor-advisoryx_refsource_HP
- http://www.securityfocus.com/bid/20588 vdb-entryx_refsource_BIDPatch
- http://www.us-cert.gov/cas/techalerts/TA06-291A.html third-party-advisoryx_refsource_CERTUS Government Resource
- http://www.vupen.com/english/advisories/2006/4065 vdb-entryx_refsource_VUPENVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 18, 2006
Updated Aug 7, 2024
Reserved Oct 17, 2006
Link CVE-2006-5336
CISA Vulnrichment
Updated n/a