Oracle October 2008 Oracle Critical Patch Update Multiple Vulnerabilities
BID:31683
Info
Oracle October 2008 Oracle Critical Patch Update Multiple Vulnerabilities
| Bugtraq ID: | 31683 |
| Class: | Unknown |
| CVE: |
CVE-2008-2619 CVE-2008-2624 CVE-2008-2625 CVE-2008-3588 CVE-2008-3975 CVE-2008-3976 CVE-2008-3977 CVE-2008-3980 CVE-2008-3982 CVE-2008-3983 CVE-2008-3984 CVE-2008-3985 CVE-2008-3986 CVE-2008-3987 CVE-2008-3988 CVE-2008-3989 CVE-2008-3990 CVE-2008-3991 CVE-2008-3992 CVE-2008-3993 CVE-2008-3994 CVE-2008-3996 CVE-2008-3998 CVE-2008-4000 CVE-2008-4001 CVE-2008-4002 CVE-2008-4003 CVE-2008-4004 CVE-2008-4005 CVE-2008-4008 CVE-2008-4009 CVE-2008-4010 CVE-2008-4011 CVE-2008-4012 CVE-2008-4013 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 14 2008 12:00AM |
| Updated: | Sep 29 2011 07:50PM |
| Credit: | Esteban Martinez Fayo of Application Security, Inc., Pete Finnigan, Tony Fogarty of DNV, guyp of Sentrigo, Jack Kanter of Integrigy, Joxean Koret, Alexander Kornbrust of Red Database Security, Slavik Markovich of Sentrigo, Amichai Shulman of Imperva, Inc., |
| Vulnerable: |
Oracle PeopleSoft Enterprise PeopleTools 8.49.14 Oracle PeopleSoft Enterprise PeopleTools 8.48.18 Oracle PeopleSoft Enterprise Customer Relationship Manage 9.0 Oracle PeopleSoft Enterprise Customer Relationship Manage 8.9 Oracle Oracle9i Enterprise Edition 9.2 .8DV Oracle Oracle9i Enterprise Edition 9.2 .8.0 Oracle Oracle11g Standard Edition One 11.1 6 Oracle Oracle11g Standard Edition 11.1 6 Oracle Oracle11g Enterprise Edition 11.1 6 Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Standard Edition 10.2 .2 Oracle Oracle10g Standard Edition 10.2.0.4 Oracle Oracle10g Personal Edition 10.2 .3 Oracle Oracle10g Personal Edition 10.2 .2 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.2 .3 Oracle Oracle10g Enterprise Edition 10.2 .2 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.4 Oracle Oracle10g Application Server 10.1.3 .4.0 Oracle Oracle10g Application Server 10.1.3 .3.0 Oracle Oracle10g Application Server 9.0.4 3 Oracle Oracle10g Application Server 10.1.2.3.0 Oracle JD Edwards EnterpriseOne 8.98 Oracle JD Edwards EnterpriseOne 8.97 Oracle E-Business Suite 12 12.0.4 Oracle E-Business Suite 11i 11.5.10.2 BEA Systems WebLogic Workshop 8.1 SP 6 BEA Systems WebLogic Workshop 8.1 SP 5 BEA Systems WebLogic Workshop 8.1 SP 4 BEA Systems WebLogic Workshop 8.1 SP 3 BEA Systems WebLogic Workshop 8.1 SP 2 BEA Systems WebLogic Workshop 9.2 BEA Systems WebLogic Workshop 9.1 BEA Systems WebLogic Workshop 9.0 BEA Systems WebLogic Workshop 10.3 GA BEA Systems WebLogic Workshop 10.2 GA BEA Systems WebLogic Workshop 10.0 MP1 BEA Systems WebLogic Workshop 10.0 BEA Systems Weblogic Server 8.1 SP 6 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 .0.1 SP 4 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 6.1 SP6 BEA Systems Weblogic Server 6.1 SP 7 BEA Systems Weblogic Server 6.1 SP 5 BEA Systems Weblogic Server 6.1 SP 4 BEA Systems Weblogic Server 6.1 SP 3 BEA Systems Weblogic Server 6.1 SP 2 BEA Systems Weblogic Server 6.1 SP 1 BEA Systems Weblogic Server 6.1 BEA Systems Weblogic Server 9.2 Maintenance Pack BEA Systems Weblogic Server 9.2 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.0 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 SP7 BEA Systems Weblogic Server 10.3 BEA Systems Weblogic Server 10.0 MP1 BEA Systems Weblogic Server 10.0 BEA WebLogic Workshop 9.2 |
| Not Vulnerable: | |
Discussion
Oracle October 2008 Oracle Critical Patch Update Multiple Vulnerabilities
Oracle has released the October 2008 critical patch update addressing 36 vulnerabilities affecting the following software:
Oracle Database
Oracle Application Server
Oracle E-Business Suite
Oracle PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise
Oracle JD Edwards EnterpriseOne Tools
Oracle WebLogic Server (formerly BEA WebLogic Server)
Oracle Workshop for WebLogic (formerly BEA WebLogic Workshop)
Oracle has released the October 2008 critical patch update addressing 36 vulnerabilities affecting the following software:
Oracle Database
Oracle Application Server
Oracle E-Business Suite
Oracle PeopleSoft Enterprise PeopleTools
Oracle PeopleSoft Enterprise
Oracle JD Edwards EnterpriseOne Tools
Oracle WebLogic Server (formerly BEA WebLogic Server)
Oracle Workshop for WebLogic (formerly BEA WebLogic Workshop)
Exploit / POC
Oracle October 2008 Oracle Critical Patch Update Multiple Vulnerabilities
Some of these issues may not require specific exploit code and may be trivial to exploit.
The following example exploits are available:
Some of these issues may not require specific exploit code and may be trivial to exploit.
The following example exploits are available:
- /data/vulnerabilities/exploits/31683-1.txt
- /data/vulnerabilities/exploits/31683-2.txt
- /data/vulnerabilities/exploits/31683-3.txt
- /data/vulnerabilities/exploits/31683-4.sql
- /data/vulnerabilities/exploits/31683-5.sql
- /data/vulnerabilities/exploits/31683-6.sql
- /data/vulnerabilities/exploits/31683-7.sql
- /data/vulnerabilities/exploits/31683-8.sql
- /data/vulnerabilities/exploits/31683-9.sql
Solution / Fix
Oracle October 2008 Oracle Critical Patch Update Multiple Vulnerabilities
Solution:
Oracle has released CPUOct2008 (Critical Patch Update October 2008) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
Oracle has released CPUOct2008 (Critical Patch Update October 2008) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.
References
Oracle October 2008 Oracle Critical Patch Update Multiple Vulnerabilities
References:
References:
- Elevation of privilege vulnerability in some NetUI tags (Oracle)
- Oracle Homepage (Oracle)
- Advisory for Oracle CPU October 2008 - APEX Flows excessive privileges (Pete Finnigan
) - CVE-2008-2625: Oracle DBMS ? Proxy Authentication Vulnerability ([email protected])
- CVE-2008-4000: Oracle PeopleTools ? Authentication Weakness ([email protected])
- iDefense Security Advisory 10.31.08: Oracle WebLogic Apache Connector (iDefense Labs
) - Team SHATTER Security Advisory: Oracle Database multiple SQL Injection vulnerab (Shatter)
- Team SHATTER Security Advisory: Oracle Database Multiple SQL Injection vulnerab (Shatter)
- Team SHATTER Security Advisory: Oracle Database SQL Injection in SYS.DBMS_CDC_I (Shatter)
- Team SHATTER Security Advisory: Oracle Database SQL Injection in SYS.DBMS_CDC_P (Shatter)
- Team SHATTER Security Advisory: Oracle Database multiple SQL Injection vulnerabi (Shatter
) - Team SHATTER Security Advisory: Oracle Database Multiple SQL Injection vulnerabi (Shatter
) - Team SHATTER Security Advisory: Oracle Database SQL Injection in SYS.DBMS_CDC_IP (Shatter
) - Team SHATTER Security Advisory: Oracle Database SQL Injection in SYS.DBMS_CDC_PU (Shatter
) - Elevation of Privilege vulnerability if more than one authorizer is used (Oracle)
- Elevation of privilege vulnerability in some NetUI pageflows (Oracle)
- Elevation of privileges for some applications (Oracle)
- Oracle Critical Patch Update Advisory - October 2008 (Oracle)
- Oracle Critical Patch Update Pre-Release Announcement - October 2008 (Oracle)
- Oracle DBMS �?? Proxy Authentication Vulnerability (Imperva)
- Oracle PeopleTools �?? Authentication Weakness (Imperva)
- Oracle WebLogic Apache Connector (iDefense Labs)
- Protected webapps may be displayed under certain conditions (Oracle)
- Security vulnerability in WebLogic plug-in for Apache (Oracle)