PT-2006-6055 · Oracle · Oracle Database

Alexander Kornbrust

+1

·

Published

2006-10-18

·

Updated

2018-10-17

·

CVE-2006-5335

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database versions 10.1.0.5 through 10.2.0.2
Description The issue involves multiple unspecified vulnerabilities with remote authenticated attack vectors. These vulnerabilities are related to the Change Data Capture (CDC) and Oracle Spatial components. Specifically, they involve sys.dbms cdc impdp, sys.dbms cdc isubscribe, and mdsys.sdo geor int. Reports from reliable third parties suggest that these issues may be related to SQL injection in certain functions.
Recommendations For Oracle Database versions 10.1.0.5 through 10.2.0.2, consider restricting access to the vulnerable components, such as the Change Data Capture (CDC) and Oracle Spatial components, until a fix is available. As a temporary workaround, consider disabling the use of the BUMP SEQUENCE, CREATE SUBSCRIPTION, EXTEND WINDOW LIST, SUBSCRIBE, and COMPRESSDATA functions to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5335

Affected Products

Oracle Database