CNCAN ID:CNCAN-2009041604
多个Oracle产品存在漏洞,可导致SQL注入,泄漏敏感信息或使攻击者破坏系统:
-Oracle Process Manager和Notification (opmn)守护程序存在格式串错误,提交特殊构建的POST请求给port 6000/TCP可导致任意代码执行。
-传递给"DBMS_AQIN"的输入在使用前缺少过滤,可导致注入任意SQL代码。
-Oracle数据库包含的Application Express组件存在错误,非特权用户可以获得"LOWS_030000.WWV_FLOW_USER"中的APEX密码HASH。
目前还存在多个未知漏洞。
Oracle Application Server 10g
Oracle BI Publisher 10.x
Oracle Database 10.x
Oracle Database 11.x
Oracle E-Business Suite 11i
Oracle E-Business Suite 12.x
Oracle Outside In HTML Export 8.x
Oracle PeopleSoft Enterprise Human Resource Management System 8.x
Oracle PeopleSoft Enterprise Human Resource Management System 9.x
Oracle PeopleSoft Enterprise Tools 8.x
Oracle XML Publisher 5.x
Oracle9i Database Enterprise Edition
Oracle9i Database Standard Edition
<a href=http://secunia.com/advisories/34693/ target=_blank rel=external nofollow>http://secunia.com/advisories/34693/</a>
<a href=http://www.zerodayinitiative.com/advisories/ZDI-09-017/ target=_blank rel=external nofollow>http://www.zerodayinitiative.com/advisories/ZDI-09-017/</a>
<a href=http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqin.html target=_blank rel=external nofollow>http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_aqin.html</a>
<a href=http://www.red-database-security.com/advisory/apex_password_hashes.html target=_blank rel=external nofollow>http://www.red-database-security.com/advisory/apex_password_hashes.html</a>
暂无评论