PT-2011-2671 · Oracle · Oracle Database Server+2
Publicado
2011-07-20
·
Atualizado
2014-10-04
·
CVE-2011-0822
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 10.1.0.5 through 10.2.0.3
Oracle Enterprise Manager Grid Control version 10.1.0.6
Description
The issue affects the confidentiality, integrity, and availability of the system, allowing remote attackers to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data via unknown vectors.
Recommendations
For Oracle Database Server versions 10.1.0.5 through 10.2.0.3, update to a version that addresses the security restrictions bypass and arbitrary SQL command execution issues.
For Oracle Enterprise Manager Grid Control version 10.1.0.6, update to a version that addresses the security restrictions bypass and sensitive data access issues.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Database
Oracle Database Server
Oracle Enterprise Manager Grid Control