Oracle July 2006 Security Update Multiple Vulnerabilities
BID:19054
CVE-2006-3698 | CVE-2006-3699 | CVE-2006-3700 | CVE-2006-3701 | CVE-2006-3702 | CVE-2006-3703 | CVE-2006-3704 | CVE-2006-3705 | CVE-2006-3706 | CVE-2006-3707 | CVE-2006-3708 | CVE-2006-3709 | CVE-2006-3710 | CVE-2006-3711 | CVE-2006-3712 | CVE-2006-3713 | CVE-2006-3714 | CVE-2006-3715 | CVE-2006-3716 | CVE-2006-3717 | CVE-2006-3718 | CVE-2006-3719 | CVE-2006-3720 | CVE-2006-3721 | CVE-2006-3722 | CVE-2006-3723 | CVE-2006-3724 |Info
Oracle July 2006 Security Update Multiple Vulnerabilities
| Bugtraq ID: | 19054 |
| Class: | Unknown |
| CVE: |
CVE-2006-3698 CVE-2006-3699 CVE-2006-3700 CVE-2006-3701 CVE-2006-3702 CVE-2006-3703 CVE-2006-3704 CVE-2006-3705 CVE-2006-3706 CVE-2006-3707 CVE-2006-3708 CVE-2006-3709 CVE-2006-3710 CVE-2006-3711 CVE-2006-3712 CVE-2006-3713 CVE-2006-3714 CVE-2006-3715 CVE-2006-3716 CVE-2006-3717 CVE-2006-3718 CVE-2006-3719 CVE-2006-3720 CVE-2006-3721 CVE-2006-3722 CVE-2006-3723 CVE-2006-3724 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 18 2006 12:00AM |
| Updated: | Mar 27 2007 09:53PM |
| Credit: | Oracle credits Esteban Martinez Fayo of Application Security, Inc.; Dr. Christian Kleinewaechter and Swen Thuemmler of infinity3 GmbH; Alexander Kornbrust of Red Database Security GmbH; and David Litchfield of Next Generation Security Software Ltd with the |
| Vulnerable: |
PeopleSoft Enterprise Portal 8.8 PeopleSoft Enterprise Portal 8.4 Oracle Workflow 11.5.9 .5 Oracle Workflow 11.5.1 Oracle Pharmaceutical Applications 4.5.2 Oracle Pharmaceutical Applications 4.5.1 Oracle Pharmaceutical Applications 4.5 Oracle Oracle9i Standard Edition 9.2 .7 Oracle Oracle9i Standard Edition 9.2 .6 Oracle Oracle9i Standard Edition 9.2 .0.5 Oracle Oracle9i Standard Edition 9.0.1 .5 FIPS Oracle Oracle9i Standard Edition 9.0.1 .5 Oracle Oracle9i Standard Edition 9.0.1 .4 Oracle Oracle9i Standard Edition 8.1.7 Oracle Oracle9i Personal Edition 9.2 .7 Oracle Oracle9i Personal Edition 9.2 .6 Oracle Oracle9i Personal Edition 9.2 .0.5 Oracle Oracle9i Personal Edition 9.0.1 .5 FIPS Oracle Oracle9i Personal Edition 9.0.1 .5 Oracle Oracle9i Personal Edition 9.0.1 .4 Oracle Oracle9i Personal Edition 8.1.7 Oracle Oracle9i Enterprise Edition 9.2 .7.0 Oracle Oracle9i Enterprise Edition 9.2 .6.0 Oracle Oracle9i Enterprise Edition 9.2 .0.5 Oracle Oracle9i Enterprise Edition 9.0.1 .5 FIPS Oracle Oracle9i Enterprise Edition 9.0.1 .5 Oracle Oracle9i Enterprise Edition 9.0.1 .4 Oracle Oracle9i Enterprise Edition 8.1.7 Oracle Oracle9i Application Server 9.2 .0.7 Oracle Oracle9i Application Server 9.2 .0.6 Oracle Oracle9i Application Server 9.0.3 .1 Oracle Oracle9i Application Server 9.0.2 .3 Oracle Oracle9i Application Server 1.0.2 .2 Oracle Oracle8 8.0.6 .3 Oracle Oracle8 8.0.6 Oracle Oracle10g Standard Edition 10.2 .2 Oracle Oracle10g Standard Edition 10.2 .1 Oracle Oracle10g Standard Edition 10.1 .4.2 Oracle Oracle10g Standard Edition 10.1 .0.5 Oracle Oracle10g Standard Edition 10.1 .0.4 Oracle Oracle10g Standard Edition 10.1 .0.3 Oracle Oracle10g Standard Edition 9.0.4 .0 Oracle Oracle10g Personal Edition 10.2 .2 Oracle Oracle10g Personal Edition 10.2 .1 Oracle Oracle10g Personal Edition 10.1 .0.4 Oracle Oracle10g Personal Edition 10.1 .0.3 Oracle Oracle10g Personal Edition 9.0.4 .0 Oracle Oracle10g Enterprise Edition 10.2 .2 Oracle Oracle10g Enterprise Edition 10.2 .1 Oracle Oracle10g Enterprise Edition 10.1 .0.4 Oracle Oracle10g Enterprise Edition 10.1 .0.3 Oracle Oracle10g Enterprise Edition 9.0.4 .0 Oracle Oracle10g Application Server 10.1.3 .0.0 Oracle Oracle10g Application Server 10.1.2 Oracle Oracle10g Application Server 9.0.4 .2 Oracle Oracle10g Application Server 9.0.4 .1 Oracle Oracle10g Application Server 9.0.4 .0 Oracle JD Edwards EnterpriseOne 8.95 _F1 Oracle JD Edwards EnterpriseOne 8.95 _B1 Oracle JD Edwards EnterpriseOne 8.96 Oracle JD Edwards EnterpriseOne 8.95.J1 Oracle JD Edwards EnterpriseOne 8.95 Oracle Enterprise Manager Grid Control 10g 10.2 .1 Oracle E-Business Suite 11i 11.5.10 CU2 Oracle E-Business Suite 11i 11.5.10 Oracle E-Business Suite 11i 11.5.9 Oracle E-Business Suite 11i 11.5.8 Oracle E-Business Suite 11i 11.5.7 Oracle E-Business Suite 11.0 Oracle Developer Suite 9.0.4 .2 Oracle Collaboration Suite Release 2 9.0.4 .2 Oracle Collaboration Suite Release 1 10.1.2 Oracle Application Server Portal 10.1.4 .0.0 Oracle Application Server 10g 9.0.4 .3 Oracle Application Server 10g 9.0.4 .2 Oracle Application Server 10g 9.0.4 .1 Oracle Application Server 10g 9.0.4 OpenLink Software OpenLink 8.0.6 HP HP-UX B.11.23 HP HP-UX B.11.11 HP HP-UX B.11.11 |
| Not Vulnerable: | |
Discussion
Oracle July 2006 Security Update Multiple Vulnerabilities
Various Oracle applications including Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Pharmaceutical Applications, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.
Oracle has released a Critical Patch Update advisory for July 2006 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by the issues as well.
These issues will be split into individual records when more information has been disclosed.
Various Oracle applications including Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Pharmaceutical Applications, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and JD Edwards EnterpriseOne are affected by multiple vulnerabilities.
Oracle has released a Critical Patch Update advisory for July 2006 to address these vulnerabilities. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by the issues as well.
These issues will be split into individual records when more information has been disclosed.
Exploit / POC
Oracle July 2006 Security Update Multiple Vulnerabilities
Some of these issues may not require an exploit.
The following exploits are available for the SYS.KUPW$WORKER [DB03] issue and the SYS.KUPM$MCP.MAIN issue:
Some of these issues may not require an exploit.
The following exploits are available for the SYS.KUPW$WORKER [DB03] issue and the SYS.KUPM$MCP.MAIN issue:
Solution / Fix
Oracle July 2006 Security Update Multiple Vulnerabilities
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - July 2006) to address these issues. Please see the update for information on obtaining and applying appropriate patches.
See the referenced advisories for more information.
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - July 2006) to address these issues. Please see the update for information on obtaining and applying appropriate patches.
See the referenced advisories for more information.
References
Oracle July 2006 Security Update Multiple Vulnerabilities
References:
References:
- Oracle Critical Patch Update - July 2006 (Oracle)
- Oracle Homepage (Oracle)
- Oracle Products Contain Multiple Vulnerabilities (US-CERT)
- SQL Injection in package SYS.DBMS_CDC_IMPDP (6980711) [DB01] (Alexander Kornbrust)
- SQL Injection in package SYS.DBMS_STATS (6980751) [DB21] (Alexander Kornbrust)
- SQL Injection in package SYS.DBMS_UPGRADE (6980717) [DB22] (Alexander Kornbrust)
- SQL Injection in package SYS.KUPW$WORKER (6980775) [DB03] (Alexander Kornbrust)