PT-2011-2671 · Oracle · Oracle Database Server+2

Published

2011-07-20

·

Updated

2014-10-04

·

CVE-2011-0822

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 10.1.0.5 through 10.2.0.3 Oracle Enterprise Manager Grid Control version 10.1.0.6
Description The issue affects the confidentiality, integrity, and availability of the system, allowing remote attackers to bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data via unknown vectors.
Recommendations For Oracle Database Server versions 10.1.0.5 through 10.2.0.3, update to a version that addresses the security restrictions bypass and arbitrary SQL command execution issues. For Oracle Enterprise Manager Grid Control version 10.1.0.6, update to a version that addresses the security restrictions bypass and sensitive data access issues. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-0822

Affected Products

Oracle Database
Oracle Database Server
Oracle Enterprise Manager Grid Control