Oracle October 2006 Security Update Multiple Vulnerabilities

BID:20588

Info

Oracle October 2006 Security Update Multiple Vulnerabilities

Bugtraq ID: 20588
Class: Unknown
CVE: CVE-2006-5376
CVE-2006-5339
CVE-2006-5368
CVE-2006-5342
CVE-2006-5348
CVE-2006-5345
CVE-2006-5361
CVE-2006-5353
CVE-2006-5350
CVE-2006-5347
CVE-2006-5366
CVE-2006-5369
CVE-2006-5332
CVE-2006-5355
CVE-2006-5352
CVE-2006-5358
CVE-2006-5334
CVE-2006-5374
CVE-2006-5371
CVE-2006-5377
CVE-2006-5340
CVE-2006-5363
CVE-2006-5337
CVE-2006-5360
CVE-2006-5336
CVE-2006-5359
CVE-2006-5356
CVE-2006-5362
CVE-2006-5365
CVE-2006-5364
CVE-2006-5344
CVE-2006-5367
CVE-2006-5341
CVE-2006-5370
CVE-2006-5333
CVE-2006-5373
CVE-2006-5349
CVE-2006-5372
CVE-2006-5346
CVE-2006-5338
CVE-2006-5378
CVE-2006-5335
CVE-2006-5375
CVE-2006-5351
CVE-2006-5357
CVE-2006-5354
CVE-2006-5343
Remote: Yes
Local: Yes
Published: Oct 17 2006 12:00AM
Updated: Mar 06 2007 09:55PM
Credit: Oracle credits the following people with the discovery of these vulnerabilities: Johannes Fahrenkrug; Sacha Faust of S.P.I. Dynamics, Inc.; Esteban Martinez Fayo of Application Security, Inc.; Alexander Kornbrust of Red Database Security GmbH; David Litchf
Vulnerable: Oracle Pharmaceutical Applications 4.5.1
Oracle Pharmaceutical Applications 4.5
Oracle PeopleSoft Enterprise Tools 8.47.4
Oracle PeopleSoft Enterprise Tools 8.47.4
Oracle PeopleSoft Enterprise Tools 8.47.3
Oracle PeopleSoft Enterprise Tools 8.47.2
Oracle PeopleSoft Enterprise Tools 8.47.1
Oracle PeopleSoft Enterprise Tools 8.46.12
Oracle PeopleSoft Enterprise Tools 8.47 GA
Oracle PeopleSoft Enterprise Tools 8.46 GA
Oracle PeopleSoft Enterprise Portal 8.9
Oracle PeopleSoft Enterprise Portal 8.8
Oracle PeopleSoft Enterprise PeopleTools 8.48
Oracle PeopleSoft Enterprise PeopleTools 8.47
Oracle PeopleSoft Enterprise PeopleTools 8.46
Oracle PeopleSoft Enterprise PeopleTools 8.22
Oracle Oracle9i Standard Edition 9.2 .7
Oracle Oracle9i Standard Edition 9.2 .6
Oracle Oracle9i Standard Edition 9.2 .0.5
Oracle Oracle9i Standard Edition 9.0.1 .5 FIPS
Oracle Oracle9i Standard Edition 9.0.1 .5
Oracle Oracle9i Standard Edition 9.0.1 .4
Oracle Oracle9i Personal Edition 9.2 .7
Oracle Oracle9i Personal Edition 9.2 .6
Oracle Oracle9i Personal Edition 9.2 .0.5
Oracle Oracle9i Personal Edition 9.0.1 .5 FIPS
Oracle Oracle9i Personal Edition 9.0.1 .5
Oracle Oracle9i Personal Edition 9.0.1 .4
Oracle Oracle9i Enterprise Edition 9.2 .7.0
Oracle Oracle9i Enterprise Edition 9.2 .6.0
Oracle Oracle9i Enterprise Edition 9.2 .0.5
Oracle Oracle9i Enterprise Edition 9.0.1 .5 FIPS
Oracle Oracle9i Enterprise Edition 9.0.1 .5
Oracle Oracle9i Enterprise Edition 9.0.1 .4
Oracle Oracle9i Application Server 9.0.3 .1
Oracle Oracle9i Application Server 9.0.2 .3
Oracle Oracle9i Application Server 1.0.2 .2
Oracle Oracle8i Standard Edition 8.1.7 .4
Oracle Oracle8i Standard Edition 8.1.7 .4
Oracle Oracle8i Enterprise Edition 8.1.7 .4.0
Oracle Oracle10g Standard Edition 10.2 .2
Oracle Oracle10g Standard Edition 10.2 .1
Oracle Oracle10g Standard Edition 10.1 .0.5
Oracle Oracle10g Standard Edition 10.1 .0.4
Oracle Oracle10g Standard Edition 10.1 .0.3
Oracle Oracle10g Personal Edition 10.2 .2
Oracle Oracle10g Personal Edition 10.2 .1
Oracle Oracle10g Personal Edition 10.1 .0.4
Oracle Oracle10g Personal Edition 10.1 .0.3
Oracle Oracle10g Enterprise Edition 10.2 .2
Oracle Oracle10g Enterprise Edition 10.2 .1
Oracle Oracle10g Enterprise Edition 10.1 .0.4
Oracle Oracle10g Enterprise Edition 10.1 .0.3
Oracle Oracle10g Application Server 10.1.3 .0.0
Oracle Oracle10g Application Server 10.1.2 .1.0
Oracle Oracle10g Application Server 10.1.2 .0.2
Oracle Oracle10g Application Server 10.1.2 .0.1
Oracle Oracle10g Application Server 10.1.2
Oracle Oracle10g Application Server 9.0.4 .2
Oracle Oracle10g Application Server 9.0.4 .1
Oracle Oracle10g Application Server 9.0.4 .0
Oracle OneWorld Tools SP23
Oracle JD Edwards EnterpriseOne 8.95 _F1
Oracle JD Edwards EnterpriseOne 8.95 _B1
Oracle JD Edwards EnterpriseOne 8.96
Oracle JD Edwards EnterpriseOne 8.95.J1
Oracle JD Edwards EnterpriseOne 8.95
Oracle HTML DB 2.0
Oracle HTML DB 1.6.1
Oracle HTML DB 1.6
Oracle HTML DB 1.5.1
Oracle HTML DB 1.5
Oracle Full Client for DBA Administrators 9iR2
Oracle E-Business Suite 11i 11.5.10 CU2
Oracle E-Business Suite 11i 11.5.10
Oracle E-Business Suite 11i 11.5.9
Oracle E-Business Suite 11i 11.5.8
Oracle E-Business Suite 11i 11.5.7
Oracle E-Business Suite 11.0
Oracle Developer Suite 10.1.2 .0.2
Oracle Developer Suite 9.0.4 .3
Oracle Developer Suite 9.0.4 .2
Oracle Developer Suite 9.0.4 .1
Oracle Developer Suite 6i
Oracle Collaboration Suite Release 2 9.0.4 .2
Oracle Collaboration Suite Release 1 10.1.2
Oracle Application Server Release 2 9.0.2 .3
Oracle Application Server 10g 9.0.4 .3
Oracle Application Server 10g 9.0.4 .2
Oracle Application Server 10g 9.0.4 .1
Oracle Application Server 10g 9.0.4
HP Oracle for OpenView 9.1.1
HP Oracle for OpenView 8.1.7
HP Oracle for OpenView 9.2
Not Vulnerable: Oracle Application Express 2.2.1
Oracle Application Express 2.2

Discussion

Oracle October 2006 Security Update Multiple Vulnerabilities

Multiple vulnerabilities affect various Oracle applications, including:

Oracle Database
Oracle Application Server
Oracle Application Express
Oracle Collaboration Suite
Oracle E-Business Suite
Oracle Pharmaceutical Applications
Oracle PeopleSoft Enterprise PeopleTools and Portal Solutions
JD Edwards EnterpriseOne
JD Edwards OneWorld Tools

Oracle has released a Critical Patch Update advisory for October 2006 to address these vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by these issues as well.

The Oracle advisory details 101 vulnerabilities in all. This BID will be updated as further analysis of the individual issues reveals more detailed information.

Exploit / POC

Oracle October 2006 Security Update Multiple Vulnerabilities

Currently we are not aware of any exploits for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].

Some of these issues may not require an exploit.

The following proofs of concept are available:

Solution / Fix

Oracle October 2006 Security Update Multiple Vulnerabilities

Solution:
Oracle has released a Critical Patch Update (October 2006) to address these issues. Please see the update for information on obtaining and applying appropriate patches.

Oracle recommends updating Oracle Application Express to version 2.2.1 to address vulnerabilities in earlier versions of the application.

See the referenced advisories for more information.


Oracle HTML DB 1.5

Oracle HTML DB 1.6.1

Oracle HTML DB 2.0

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report