Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
BID:16384
Info
Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
| Bugtraq ID: | 16384 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 25 2006 12:00AM |
| Updated: | Feb 08 2006 09:53PM |
| Credit: | David Litchfield is credited with the discovery of this vulnerability. |
| Vulnerable: |
Stonesoft StoneBeat High Availability 9.0.2 release 2 Stonesoft StoneBeat High Availability 9.0.2 .0.1 Release 2 Oracle Oracle9i Application Server 9.2 .0.7 Oracle Oracle9i Application Server 9.2 .0.6 Oracle Oracle9i Application Server 9.0.3 .1 Oracle Oracle9i Application Server 9.0.3 Oracle Oracle9i Application Server 9.0.2 .3 Oracle Oracle9i Application Server 9.0.2 .2 Oracle Oracle9i Application Server 9.0.2 .1 Oracle Oracle9i Application Server 9.0.2 .0.1 Oracle Oracle9i Application Server 9.0.2 .0.0 Oracle Oracle9i Application Server 9.0.2 Oracle Oracle9i Application Server 1.0.2 .2.2 Oracle Oracle9i Application Server 1.0.2 .2 Oracle Oracle9i Application Server 1.0.2 .1s Oracle Oracle9i Application Server 1.0.2 Oracle Oracle9i Application Server Oracle Oracle10g Application Server 10.1.2 .1.0 Oracle Oracle10g Application Server 10.1.2 .0.2 Oracle Oracle10g Application Server 10.1.2 .0.1 Oracle Oracle10g Application Server 10.1.2 Oracle Oracle10g Application Server 10.1 .0.4 Oracle Oracle10g Application Server 10.1 .0.3.1 Oracle Oracle10g Application Server 10.1 .0.3 Oracle Oracle10g Application Server 10.1 .0.2 Oracle Oracle10g Application Server 9.0.4 .2 Oracle Oracle10g Application Server 9.0.4 .1 Oracle Oracle10g Application Server 9.0.4 .0 Oracle Oracle HTTP Server for Apps only 1.0.2 .1s Oracle Oracle HTTP Server 9.2 .0 Oracle Oracle HTTP Server 9.1 Oracle Oracle HTTP Server 9.0.3 .1 Oracle Oracle HTTP Server 9.0.2 .3 Oracle Oracle HTTP Server 9.0.2 Oracle Oracle HTTP Server 9.0.1 Oracle Oracle HTTP Server 8.1.7 Oracle Oracle HTTP Server 1.0.2 .2 Roll up 2 Oracle Oracle HTTP Server 1.0.2 .2 Oracle Oracle HTTP Server 1.0.2 .1 Oracle Oracle HTTP Server 1.0.2 .0 Oracle Internet Application Server 1.0.2 .1 Oracle Internet Application Server 1.0.2 .0 Oracle Applications 11i 11.5.10 CU2 Oracle Applications 11i 11.5.10 Oracle Applications 11i 11.5.9 Oracle Applications 11i 11.5.1 Oracle Application Server 10g 10.1.2 |
| Not Vulnerable: | |
Discussion
Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
Oracle PL/SQL gateway is prone to a vulnerability that permits the bypassing of an access control list (ACL). This issue is due to an error in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to bypass the exclusion list and to gain access to excluded packages and procedures running in the context of the DBA; this may facilitate privilege escalation.
Successful exploitation may facilitate a compromise of the database server and enable an attacker to gain full DBA access.
Oracle PL/SQL gateway is prone to a vulnerability that permits the bypassing of an access control list (ACL). This issue is due to an error in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to bypass the exclusion list and to gain access to excluded packages and procedures running in the context of the DBA; this may facilitate privilege escalation.
Successful exploitation may facilitate a compromise of the database server and enable an attacker to gain full DBA access.
Exploit / POC
Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Oracle PL/SQL Gateway PLSQLExclusion Access Control List Bypass Vulnerability
References:
References:
- mod_plsql Security Bug Disclosure and Workaround (Integrity)
- Oracle Homepage (Oracle)
- More on the workaround for the unpatched Oracle PLSQL Gateway flaw ("David Litchfield"
) - Re: Workaround for unpatched Oracle PLSQL Gateway flaw ("David Litchfield"
) - The History of the Oracle PLSQL Gateway Flaw ("David Litchfield"
) - Workaround for unpatched Oracle PLSQL Gateway flaw (David Litchfield)