PT-2005-4242 · Oracle · Oracle Database Server+3

Publicado

2005-11-02

·

Atualizado

2012-10-23

·

CVE-2005-3446

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions up to 9.2.0.6 Oracle Application Server versions up to 10.1.2.0
Description The issue allows remote attackers to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data. The impact and attack vectors of an unspecified vulnerability in Internet Directory are unknown.
Recommendations For Oracle Database Server versions up to 9.2.0.6, update to a version that addresses the security restrictions bypass issue. For Oracle Application Server versions up to 10.1.2.0, update to a version that addresses the security restrictions bypass issue. As a temporary workaround, consider restricting access to sensitive data and limiting the execution of arbitrary SQL commands until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3446

Produtos afetados

Internet Directory
Oracle Application Server
Oracle Database
Oracle Database Server