Oracle July Security Update Multiple Vulnerabilities
BID:14238
Info
Oracle July Security Update Multiple Vulnerabilities
| Bugtraq ID: | 14238 |
| Class: | Unknown |
| CVE: |
CVE-2003-0993 CVE-2004-0700 CVE-2004-1029 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery of these issues is credited to Gerhard Eschelbeck of Qualys, Esteban Martínez Fayó of Application Security, Inc., Alexander Kornbrust of Red Database Security, Stephen Kost of Integrigy, David Litchfield of NGSS, Michael Murray of nCircle Netwo |
| Vulnerable: |
Oracle Workflow 11.5.9 .5 Oracle Workflow 11.5.1 Oracle Oracle9i Standard Edition 9.2 .6 Oracle Oracle9i Standard Edition 9.2 .0.5 Oracle Oracle9i Standard Edition 9.0.1 .5 Oracle Oracle9i Standard Edition 9.0.1 .4 Oracle Oracle9i Personal Edition 9.2 .6 Oracle Oracle9i Personal Edition 9.2 .0.5 Oracle Oracle9i Personal Edition 9.0.1 .5 Oracle Oracle9i Personal Edition 9.0.1 .4 Oracle Oracle9i Enterprise Edition 9.2 .6.0 Oracle Oracle9i Enterprise Edition 9.2 .0.5 Oracle Oracle9i Enterprise Edition 9.0.1 .5 Oracle Oracle9i Enterprise Edition 9.0.1 .4 Oracle Oracle9i Application Server 9.0.3 .1 Oracle Oracle9i Application Server 9.0.2 .3 Oracle Oracle9i Application Server 1.0.2 .2 Oracle Oracle8i Standard Edition 8.1.7 .4 Oracle Oracle8i Enterprise Edition 8.1.7 .4.0 Oracle Oracle8 8.0.6 .3 Oracle Oracle8 8.0.6 Oracle Oracle10g Standard Edition 10.1 .0.4 Oracle Oracle10g Standard Edition 10.1 .0.3 Oracle Oracle10g Standard Edition 10.1 .0.2 Oracle Oracle10g Personal Edition 10.1 .0.4 Oracle Oracle10g Personal Edition 10.1 .0.3 Oracle Oracle10g Personal Edition 10.1 .0.2 Oracle Oracle10g Enterprise Edition 10.1 .0.4 Oracle Oracle10g Enterprise Edition 10.1 .0.3 Oracle Oracle10g Enterprise Edition 10.1 .0.2 Oracle Oracle10g Application Server 9.0.4 .1 Oracle Oracle10g Application Server 9.0.4 .0 Oracle JInitiator 1.3.1 Oracle JInitiator 1.1.8 Oracle Forms And Reports 6.0.8 .25 Oracle Forms And Reports 4.5.10 .22 Oracle Express Server 6.3.4 .0 Oracle Enterprise Manager Grid Control 10g 10.1 .3 Oracle Enterprise Manager Grid Control 10g 10.1 .0.2 Oracle Enterprise Manager Database Control 10g 10.1 .0.4 Oracle Enterprise Manager Database Control 10g 10.1 .0.3 Oracle Enterprise Manager Database Control 10g 10.1 .0.2 Oracle Enterprise Manager Application Server Control 9.0.4 .1 Oracle Enterprise Manager Application Server Control 9.0.4 .0 Oracle E-Business Suite 11i 11.5.10 Oracle E-Business Suite 11i 11.5.9 Oracle E-Business Suite 11i 11.5.8 Oracle E-Business Suite 11i 11.5.7 Oracle E-Business Suite 11i 11.5.6 Oracle E-Business Suite 11i 11.5.5 Oracle E-Business Suite 11i 11.5.4 Oracle E-Business Suite 11i 11.5.3 Oracle E-Business Suite 11i 11.5.2 Oracle E-Business Suite 11i 11.5.1 Oracle E-Business Suite 11.0 Oracle Developer Suite 10.1.2 Oracle Developer Suite 9.0.5 Oracle Developer Suite 9.0.4 .1 Oracle Developer Suite 9.0.4 Oracle Developer Suite 9.0.2 .3 Oracle Collaboration Suite Release 2 9.0.4 .2 Oracle Collaboration Suite Release 2 9.0.4 .1 HP HP-UX B.11.23 HP HP-UX B.11.11 |
| Not Vulnerable: | |
Discussion
Oracle July Security Update Multiple Vulnerabilities
Various Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Workflow, Oracle Forms and Reports, Oracle JInitiator, Oracle Developer Suite, and Oracle Express Server are affected by multiple vulnerabilities.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.
Oracle has released a Critical Patch Update advisory for July 2005 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Various Oracle Database Server, Oracle Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Workflow, Oracle Forms and Reports, Oracle JInitiator, Oracle Developer Suite, and Oracle Express Server are affected by multiple vulnerabilities.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats.
Oracle has released a Critical Patch Update advisory for July 2005 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Exploit / POC
Oracle July Security Update Multiple Vulnerabilities
An exploit would not be required for some of these issues such as the SQL injection vulnerabilities. Other issues would likely require exploit code.
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
An exploit would not be required for some of these issues such as the SQL injection vulnerabilities. Other issues would likely require exploit code.
---
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Oracle July Security Update Multiple Vulnerabilities
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - July 2005) to address these issues. Information regarding obtaining and applying an appropriate patch can be found in the Oracle Critical Patch Update in references.
Pre-installation notes for Oracle Database Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311062.1
Pre-installation notes for Oracle Application Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311038.1
Pre-installation notes for Oracle Collaboration Suite can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311039.1
Pre-installation notes for Oracle E-Business and Applications can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311040.1
Pre-installation notes for Oracle Enterprise Manager can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311061.1
HP has released advisory HPSBMA01211 (SSRT4682 rev.0 - Oracle for Openview (OfO) Critical Patch Update July 2005) to identify vulnerable HP packages and fixes. HP advises users of Oracle for Openview who have support contracts with Oracle to obtain Critical Patch Update - July 2005 from Oracle. Users of Oracle for Openview who have support contracts with HP can contact HP for fixes. Please see the referenced advisory for more information.
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - July 2005) to address these issues. Information regarding obtaining and applying an appropriate patch can be found in the Oracle Critical Patch Update in references.
Pre-installation notes for Oracle Database Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311062.1
Pre-installation notes for Oracle Application Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311038.1
Pre-installation notes for Oracle Collaboration Suite can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311039.1
Pre-installation notes for Oracle E-Business and Applications can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311040.1
Pre-installation notes for Oracle Enterprise Manager can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311061.1
HP has released advisory HPSBMA01211 (SSRT4682 rev.0 - Oracle for Openview (OfO) Critical Patch Update July 2005) to identify vulnerable HP packages and fixes. HP advises users of Oracle for Openview who have support contracts with Oracle to obtain Critical Patch Update - July 2005 from Oracle. Users of Oracle for Openview who have support contracts with HP can contact HP for fixes. Please see the referenced advisory for more information.
References
Oracle July Security Update Multiple Vulnerabilities
References:
References:
- Critical Patch Update - July 2005 (Oracle)
- Integrigy Security Analysis (Integrigy Security)
- Oracle Forms Builder Password in Temp Files (Red Database Security)
- Oracle Forms Insecure Temporary File Handling (Red Database Security)
- Oracle JDeveloper passes Plaintext Password (Red Database Security)
- Oracle JDeveloper Plaintext Passwords (Red Database Security)
- [Argeniss] Oracle 9R2 Unpatched vulnerability on CWM2_OLAP_AW_AWUTIL package (Cesar
) - Multiple High Risk Vulnerabilities in Oracle E-Business Suite 11i - Critical Pat ("Integrigy Security"
)