Oracle Diagnostics Multiple Vulnerabilities
BID:16844
Info
Oracle Diagnostics Multiple Vulnerabilities
| Bugtraq ID: | 16844 |
| Class: | Unknown |
| CVE: |
CVE-2006-1037 CVE-2006-1035 CVE-2006-1036 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2006 12:00AM |
| Updated: | Jun 27 2007 10:18PM |
| Credit: | The original discoverer of these issues is currently unknown. These issues were disclosed by the vendor. |
| Vulnerable: |
Oracle Diagnostics 2.2 Oracle Diagnostics 2.1 Oracle Diagnostics 2.0 Oracle Applications 11i 11.5.10 CU2 Oracle Applications 11i 11.5.10 CU1 Oracle Applications 11i 11.5.10 Oracle Applications 11i 11.5.9 Oracle Applications 11i 11.5.8 Oracle Applications 11i 11.5.7 Oracle Applications 11i 11.5.6 Oracle Applications 11i 11.5.5 Oracle Applications 11i 11.5.4 Oracle Applications 11i 11.5.3 |
| Not Vulnerable: |
Oracle Diagnostics 2.3 |
Discussion
Oracle Diagnostics Multiple Vulnerabilities
The Oracle Diagnostics module is susceptible to multiple vulnerabilities. These issues include insecure permissions, insecure default access, and SQL injection.
- Insecure-permissions vulnerability. This may allow remote attackers to gain access to potentially sensitive information that may aid them in further attacks.
- Default-access vulnerabilities. Successful exploits could allow an attacker to gain access to potentially sensitive information that may aid them in further attacks.
- Unspecified SQL-injection issues. Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Oracle has released the 'Diagnostics Support Pack February 2006' with 'Oracle Diagnostics 2.3 RUP A' to address these vulnerabilities. This update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Other issues may have also been addressed with these fixes. This BID will be updated as further information is disclosed.
The Oracle Diagnostics module is susceptible to multiple vulnerabilities. These issues include insecure permissions, insecure default access, and SQL injection.
- Insecure-permissions vulnerability. This may allow remote attackers to gain access to potentially sensitive information that may aid them in further attacks.
- Default-access vulnerabilities. Successful exploits could allow an attacker to gain access to potentially sensitive information that may aid them in further attacks.
- Unspecified SQL-injection issues. Successful exploits could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Oracle has released the 'Diagnostics Support Pack February 2006' with 'Oracle Diagnostics 2.3 RUP A' to address these vulnerabilities. This update addresses the vulnerabilities for supported releases. Earlier, unsupported releases are likely to be affected by the issues as well.
Other issues may have also been addressed with these fixes. This BID will be updated as further information is disclosed.
Exploit / POC
Oracle Diagnostics Multiple Vulnerabilities
These issues would likely be exploited from a web browser.
An example URI to a diagnostic test file was provided:
http://www.example.com/OA_HTML/jtfqalgn.htm
These issues would likely be exploited from a web browser.
An example URI to a diagnostic test file was provided:
http://www.example.com/OA_HTML/jtfqalgn.htm
Solution / Fix
Oracle Diagnostics Multiple Vulnerabilities
Solution:
Oracle has released an updated Oracle Diagnostics version 2.3 to address these issues. Contact the vendor for information on obtaining fixes.
Solution:
Oracle has released an updated Oracle Diagnostics version 2.3 to address these issues. Contact the vendor for information on obtaining fixes.
References
Oracle Diagnostics Multiple Vulnerabilities
References:
References: