Oracle9i 9.0.1.5 FIPS Single Sign-On Server Unspecified Cross-Site Scripting Vulnerability
BID:14281
Info
Oracle9i 9.0.1.5 FIPS Single Sign-On Server Unspecified Cross-Site Scripting Vulnerability
| Bugtraq ID: | 14281 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2005 12:00AM |
| Updated: | Jul 15 2005 12:00AM |
| Credit: | This issue was announced by Oracle. |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.0.1 .5 FIPS Oracle Oracle9i Personal Edition 9.0.1 .5 FIPS Oracle Oracle9i Enterprise Edition 9.0.1 .5 FIPS |
| Not Vulnerable: | |
Discussion
Oracle9i 9.0.1.5 FIPS Single Sign-On Server Unspecified Cross-Site Scripting Vulnerability
An unspecified cross-site scripting vulnerability exists in the Single Sign-On Server (SSO) for Oracle Database Server.
This issue could likely be exploited by enticing a victim to visit a malicious link that includes hostile HTML and script code. Theft of cookie-based authentication credentials from legitimate users could result from exploitation. Other attacks may also be possible.
This issue was mentioned in the patch readme for the Oracle Critical Patch Update for July. Oracle has not released any further information about this vulnerability.
An unspecified cross-site scripting vulnerability exists in the Single Sign-On Server (SSO) for Oracle Database Server.
This issue could likely be exploited by enticing a victim to visit a malicious link that includes hostile HTML and script code. Theft of cookie-based authentication credentials from legitimate users could result from exploitation. Other attacks may also be possible.
This issue was mentioned in the patch readme for the Oracle Critical Patch Update for July. Oracle has not released any further information about this vulnerability.
Exploit / POC
Oracle9i 9.0.1.5 FIPS Single Sign-On Server Unspecified Cross-Site Scripting Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Oracle9i 9.0.1.5 FIPS Single Sign-On Server Unspecified Cross-Site Scripting Vulnerability
Solution:
This issue is addressed in the Oracle Critical Patch Update - July 2005.
Pre-installation notes for Oracle Database Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311062.1
Solution:
This issue is addressed in the Oracle Critical Patch Update - July 2005.
Pre-installation notes for Oracle Database Server can be found at the following location:
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=311062.1
References
Oracle9i 9.0.1.5 FIPS Single Sign-On Server Unspecified Cross-Site Scripting Vulnerability
References:
References:
- Critical Patch Update - July 2005 (Oracle)
- Oracle CPU July 2005 - Silently fixed bugs (Red Database Security)