Oracle April 2008 Critical Patch Update Multiple Vulnerabilities
BID:28725
Info
Oracle April 2008 Critical Patch Update Multiple Vulnerabilities
| Bugtraq ID: | 28725 |
| Class: | Unknown |
| CVE: |
CVE-2008-1811 CVE-2008-1812 CVE-2008-1813 CVE-2008-1814 CVE-2008-1815 CVE-2008-1816 CVE-2008-1817 CVE-2008-1818 CVE-2008-1819 CVE-2008-1820 CVE-2008-1821 CVE-2008-1822 CVE-2008-1823 CVE-2008-1824 CVE-2008-1825 CVE-2008-1826 CVE-2008-1827 CVE-2008-1828 CVE-2008-1829 CVE-2008-1830 CVE-2008-1831 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Apr 10 2008 12:00AM |
| Updated: | Dec 17 2008 05:42PM |
| Credit: | Cesar Cerrudo of Argeniss, Esteban Martinez Fayo of Application Security, Inc., Alexander Kornbrust of Red Database Security, Stephen Kost of Integrigy, Ali Kumcu of inTellectPro, Amichai Shulman of Imperva, Inc., Sumit Siddharth of Portcullis Computer Sec |
| Vulnerable: |
Oracle Siebel SimBuilder 7.8.5 Oracle Siebel SimBuilder 7.8.2 Oracle PeopleSoft Enterprise PeopleTools 8.49.9 Oracle PeopleSoft Enterprise PeopleTools 8.48.16 Oracle PeopleSoft Enterprise PeopleTools 8.22.19 Oracle PeopleSoft Enterprise Human Capital Management 9.0 Oracle PeopleSoft Enterprise Human Capital Management 8.9 Oracle PeopleSoft Enterprise Human Capital Management 8.8 SP1 Oracle Oracle9i Standard Edition 9.2 .8DV Oracle Oracle9i Standard Edition 9.2 .8 Oracle Oracle9i Personal Edition 9.2 .8DV Oracle Oracle9i Personal Edition 9.2 .8 Oracle Oracle9i Enterprise Edition 9.2 .8DV Oracle Oracle9i Enterprise Edition 9.2 .8.0 Oracle Oracle11g Standard Edition One 11.1 6 Oracle Oracle11g Standard Edition 11.1 6 Oracle Oracle11g Standard Edition 11.1 6 Oracle Oracle11g Enterprise Edition 11.1 6 Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Standard Edition 10.2 .2 Oracle Oracle10g Standard Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2 .3 Oracle Oracle10g Personal Edition 10.2 .2 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2 .3 Oracle Oracle10g Enterprise Edition 10.2 .2 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.2 64 bit Oracle Oracle10g Application Server 10.1.3 .3.0 Oracle Oracle10g Application Server 10.1.3 .1.0 Oracle Oracle10g Application Server 10.1.2 .2.0 Oracle Oracle10g Application Server 10.1.2 .1.0 Oracle Oracle10g Application Server 10.1.2 .0.2 Oracle Oracle10g Application Server 9.0.4 3 Oracle E-Business Suite Release 12 12.0.2 Oracle E-Business Suite Release 12 12.0 Oracle E-Business Suite 12 12.0.4 Oracle E-Business Suite 12 12.0.3 Oracle E-Business Suite 12 12.0.2 Oracle E-Business Suite 12 12.0.1 Oracle E-Business Suite 12 12.0 Oracle E-Business Suite 11i 11.5.10 CU2 Oracle E-Business Suite 11i 11.5.10 Oracle E-Business Suite 11i 11.5.9 Oracle Collaboration Suite 10g 10.1.2 HP Oracle for OpenView 9.2 HP Oracle for OpenView 9.1.1 HP Oracle for OpenView 8.1.7 HP Oracle for OpenView 9.2 HP Oracle for OpenView 10gR2 HP Oracle for OpenView 10g |
| Not Vulnerable: | |
Discussion
Oracle April 2008 Critical Patch Update Multiple Vulnerabilities
Oracle has released its critical patch update for April 2008. The advisory addresses 41 vulnerabilities affecting Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and Oracle Siebel SimBuilder.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to leverage some of the issues, but other issues do not require any authorization. The most severe of the vulnerabilities could possibly compromise affected computers.
Oracle has released its critical patch update for April 2008. The advisory addresses 41 vulnerabilities affecting Oracle Database, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite and Applications, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise, and Oracle Siebel SimBuilder.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to leverage some of the issues, but other issues do not require any authorization. The most severe of the vulnerabilities could possibly compromise affected computers.
Exploit / POC
Oracle April 2008 Critical Patch Update Multiple Vulnerabilities
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code and may be trivial to exploit.
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Some of these issues may not require specific exploit code and may be trivial to exploit.
Solution / Fix
Oracle April 2008 Critical Patch Update Multiple Vulnerabilities
Solution:
Oracle has released CPUApr2008 (Critical Patch Update April 2008) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
Oracle has released CPUApr2008 (Critical Patch Update April 2008) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.
References
Oracle April 2008 Critical Patch Update Multiple Vulnerabilities
References:
References:
- Oracle DBMS �?? Access Control Bypass with Direct Path Export (Imperva)
- Oracle Homepage (Oracle)
- iDefense Security Advisory 04.15.08: Oracle Application Express Privilege Escala (iDefense Labs
) - Team SHATTER Security Advisory: Oracle Database Buffer Overflow in SYS.DBMS_AQJM (Team SHATTER
) - Team SHATTER Security Advisory: Oracle Database Buffer Overflow in SYS.KUPF$FILE (Team SHATTER
) - Team SHATTER Security Advisory: Oracle Database SQL Injection in SYS.DBMS_CDC_UT (Team SHATTER
) - Hardcoded Password and Password Reset of OUTLN User [DB13] (Alexander Kornbrust)
- Oracle Application Express Privilege Escalation Vulnerability (iDefense Labs)
- Oracle Critical Patch Update Advisory - April 2008 (Oracle)
- Oracle E-Business Suite Business Intelligence SQL Injection Vulnerability (ZDI)
- SQL Injection in package SDO_GEOM [DB06] (Alexander Kornbrust)
- SQL Injection in package SDO_IDX [DB07] (Alexander Kornbrust)
- SQL Injection in package SDO_UTIL [DB05] (Alexander Kornbrust)