PT-2011-2700 · Oracle · Oracle Database Server+1

Published

2011-07-20

·

Updated

2011-10-05

·

CVE-2011-0852

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 10.1.0.5, 10.2.0.3, 10.2.0.4 Oracle Enterprise Manager Grid Control version 10.1.0.6
Description The issue affects the Security Management component, allowing remote attackers to impact confidentiality, integrity, and availability. The attack vectors related to Audit Administration are unknown.
Recommendations For Oracle Database Server versions 10.1.0.5, 10.2.0.3, and 10.2.0.4, update to a version that includes the fix for this issue. For Oracle Enterprise Manager Grid Control version 10.1.0.6, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Audit Administration component until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2011-0852

Affected Products

Oracle Database Server
Oracle Enterprise Manager Grid Control