PT-2012-3489 · Oracle · Oracle Enterprise Manager Grid Control Em Base Platform+3
Published
2012-07-17
·
Updated
2017-08-29
·
CVE-2012-1737
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 11.1.0.7, 11.2.0.2, and 11.2.0.3
Enterprise Manager Grid Control EM Base Platform version 10.2.0.5
Enterprise Manager Grid Control EM Base Platform version 11.1.0.1
EM Plugin for DB version 12.1.0.1
EM Plugin for DB version 12.1.0.2
Description
The issue allows remote attackers to affect confidentiality, integrity, and availability. It is related to DB Performance Advisories/UIs. Remote attackers can bypass security restrictions, execute arbitrary SQL commands, and gain access to sensitive data.
Recommendations
For Oracle Database Server versions 11.1.0.7, 11.2.0.2, and 11.2.0.3, update to a version that includes the necessary security patches.
For Enterprise Manager Grid Control EM Base Platform version 10.2.0.5, apply the recommended security fixes.
For Enterprise Manager Grid Control EM Base Platform version 11.1.0.1, EM Plugin for DB version 12.1.0.1, and EM Plugin for DB version 12.1.0.2, restrict access to sensitive data and apply security restrictions to prevent arbitrary SQL command execution.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Em Plugin For Db
Oracle Enterprise Manager Grid Control Em Base Platform
Oracle Database
Oracle Database Server