PT-2008-4046 · Oracle · Oracle Database
Published
2008-07-15
·
Updated
2018-10-11
·
CVE-2008-2592
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Database versions 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6
Description
The issue is related to the Advanced Replication component and has remote authenticated attack vectors. It is associated with
SYS.DBMS DEFER SYS and potentially involves the DELETE TRAN procedure, which may be vulnerable to SQL injection. The impact of this issue is unknown.Recommendations
For Oracle Database version 9.0.1.5 FIPS+, update to a version that is not affected by this issue.
For Oracle Database version 9.2.0.8, update to a version that is not affected by this issue.
For Oracle Database version 9.2.0.8DV, update to a version that is not affected by this issue.
For Oracle Database version 10.1.0.5, update to a version that is not affected by this issue.
For Oracle Database version 10.2.0.4, update to a version that is not affected by this issue.
For Oracle Database version 11.1.0.6, update to a version that is not affected by this issue.
As a temporary workaround, consider restricting access to the
SYS.DBMS DEFER SYS and DELETE TRAN procedure until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database