RETIRED: Oracle July 2009 Critical Patch Update Multiple Vulnerabilities
BID:35618
Info
RETIRED: Oracle July 2009 Critical Patch Update Multiple Vulnerabilities
| Bugtraq ID: | 35618 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 09 2009 12:00AM |
| Updated: | Jul 15 2009 05:46PM |
| Credit: | Anonymous of TippingPoint (3com); Esteban Martinez Fayo of Application Security, Inc.; Kowsik Guruswamy of Mu Security; Joxean Koret; Alexander Kornbrust of Red Database Security; David Litchfield of NGS Software; Oleg P. of HSC Security Portal; Alexandr P |
| Vulnerable: |
Oracle Weblogic Server 9.3 MP3 Oracle Weblogic Server 9.2 Oracle Weblogic Server 9.1 GA Oracle Weblogic Server 9.0 GA Oracle Weblogic Server 8.1 SP6 Oracle Weblogic Server 8.1 Oracle Weblogic Server 7.0 SP7 Oracle Weblogic Server 7.0 Oracle Weblogic Server 10.3 Oracle Weblogic Server 10.0 MP1 Oracle WebLogic Event Server 2.0 Oracle Siebel Highly Interactive Client 7.7.2 Oracle Siebel Highly Interactive Client 7.5.3 Oracle Siebel Highly Interactive Client 8.1 Oracle Siebel Highly Interactive Client 8.0 Oracle Siebel Highly Interactive Client 7.8 Oracle PeopleSoft Enterprise PeopleTools 8.49 Oracle PeopleSoft Enterprise HRMS 9.0 Oracle PeopleSoft Enterprise HRMS 8.9 Oracle Oracle9i Standard Edition 9.2 .8DV Oracle Oracle9i Standard Edition 9.2 .8 Oracle Oracle9i Personal Edition 9.2 .8DV Oracle Oracle9i Personal Edition 9.2 .8 Oracle Oracle9i Enterprise Edition 9.2 .8DV Oracle Oracle9i Enterprise Edition 9.2 .8.0 Oracle Oracle11g Standard Edition 11.1 6 Oracle Oracle11g Standard Edition 11.1 .7 Oracle Oracle11g Enterprise Edition 11.1 6 Oracle Oracle11g Enterprise Edition 11.1.0.7 Oracle Oracle10g Standard Edition 10.2 .3 Oracle Oracle10g Standard Edition 10.2.0.4 Oracle Oracle10g Personal Edition 10.2 .3 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.2 .3 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.4 Oracle Oracle10g Application Server 10.1.3 .4.0 Oracle Oracle10g Application Server 10.1.3 .3.0 Oracle Oracle10g Application Server 10.1.2 Oracle Oracle10g Application Server 10.1.2.3.0 Oracle Oracle Identity Management 10g 10.1.4 .3.0 Oracle Oracle Identity Management 10g 10.1.4 .2.0 Oracle Oracle Identity Management 10g 10.1.4 .0.1 Oracle JRockit R27.6.3 Oracle JRockit R27.6.2 Oracle JRockit R27.6.0 Oracle Enterprise Manager Grid Control 10g 10.2.0.4 Oracle Enterprise Manager Database Control 11i 11.1.0.6 Oracle Enterprise Manager Database Control 11g 11.1.0.7 Oracle E-Business Suite 12 12.1 Oracle E-Business Suite 11i 11.5.10 Oracle E-Business Suite 12.0.6 Oracle Complex Event Processing 10.3 BEA Systems Weblogic Server 9.2.2 BEA Systems Weblogic Server 9.2.1 BEA Systems Weblogic Server 9.2 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 8.1.6 BEA Systems Weblogic Server 8.1.4 BEA Systems Weblogic Server 8.1 SP 6 BEA Systems Weblogic Server 8.1 SP 5 BEA Systems Weblogic Server 8.1 SP 4 BEA Systems Weblogic Server 8.1 SP 3 BEA Systems Weblogic Server 8.1 SP 2 BEA Systems Weblogic Server 8.1 SP 1 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0.5 BEA Systems Weblogic Server 7.0.4 BEA Systems Weblogic Server 7.0.2 BEA Systems Weblogic Server 7.0 .0.1 SP 4 BEA Systems Weblogic Server 7.0 .0.1 SP 3 BEA Systems Weblogic Server 7.0 .0.1 SP 2 BEA Systems Weblogic Server 7.0 .0.1 SP 1 BEA Systems Weblogic Server 7.0 .0.1 BEA Systems Weblogic Server 7.0 SP 7 BEA Systems Weblogic Server 7.0 SP 6 BEA Systems Weblogic Server 7.0 SP 5 BEA Systems Weblogic Server 7.0 SP 4 BEA Systems Weblogic Server 7.0 SP 3 BEA Systems Weblogic Server 7.0 SP 2 BEA Systems Weblogic Server 7.0 SP 1 BEA Systems Weblogic Server 7.0 BEA Systems Weblogic Server 9.2 Maintenance Pack BEA Systems Weblogic Server 9.2 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.1 BEA Systems Weblogic Server 9.0 BEA Systems Weblogic Server 8.1 SP6 BEA Systems Weblogic Server 8.1 BEA Systems Weblogic Server 7.0 SP7 BEA Systems Weblogic Server 10.3 BEA Systems Weblogic Server 10.3 BEA Systems Weblogic Server 10.0 MP1 BEA Systems Weblogic Server 10.0 Maintenance Pac BEA Systems Weblogic Server 10.0 BEA Systems Weblogic Server 10.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Oracle July 2009 Critical Patch Update Multiple Vulnerabilities
Oracle has released the July 2009 critical patch update, which addresses 29 vulnerabilities.
The following individual records document these issues:
35698 Oracle Highly Interactive Client CVE-2009-1981 Unspecified Local Vulnerability
35697 Oracle E-Business Suite CVE-2009-1983 Remote Oracle iStore Vulnerability
35694 Oracle PeopleSoft CVE-2009-1989 Remote PeopleSoft Enterprise FMS Vulnerability
35689 Oracle Database CVE-2009-1969 Remote Auditing Vulnerability
35684 Oracle Database CVE-2009-1020 Network Foundation Remote Vulnerability
35688 Oracle Application Server CVE-2009-1976 Remote HTTP Server Vulnerability
35690 Oracle E-Business Suite CVE-2009-1984 Application Install Local Vulnerability
35692 Oracle Config Management CVE-2009-1967 Remote Unspecified Vulnerability
35686 Oracle E-Business Suite CVE-2009-1980 Remote Vulnerability
35682 Oracle Database CVE-2009-1015 Remote Core RDBMS Vulnerability
35680 Oracle Database CVE-2009-1019 Remote Network Authentication Vulnerability
35687 Oracle Database CVE-2009-1973 Remote Virtual Private Database Vulnerability
35677 Oracle Database CVE-2009-1963 Remote Network Foundation Vulnerability
35685 Oracle Advanced Replication CVE-2009-1021 Remote Unspecified Vulnerability
35681 Oracle Database CVE-2009-1968 Remote Secure Enterprise Search Vulnerability
35678 Oracle Secure Backup CVE-2009-1978 Remote Oracle Secure Backup Vulnerability
35683 Oracle Database CVE-2009-1970 Remote Listener Vulnerability
34800 Jetty Cross Site Scripting and Information Disclosure Vulnerabilities
35672 Oracle Secure Backup CVE-2009-1977 Remote Oracle Secure Backup Vulnerability
35679 Oracle Database CVE-2009-0987 Remote Upgrade Vulnerability
35676 Oracle Config Management CVE-2009-1966 Unspecified Security Vulnerability
35674 Oracle WebLogic Server CVE-2009-1974 Remote Vulnerability
35673 Oracle Weblogic Server CVE-2009-1975 Remote Vulnerability
35696 Oracle PeopleSoft Enterprise HRMS eProfile Manager CVE-2009-1988 Remote Vulnerability
35695 Oracle E-Business Suite CVE-2009-1986 Remote Oracle Applications Manager Vulnerability
35693 Oracle E-Business Suite CVE-2009-1982 Remote Oracle Applications Framework Vulnerability
35691 Oracle PeopleSoft Enterprise PeopleTools CVE-2009-1987 Unspecified Remote Vulnerability
35671 IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
34240 Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
Oracle has released the July 2009 critical patch update, which addresses 29 vulnerabilities.
The following individual records document these issues:
35698 Oracle Highly Interactive Client CVE-2009-1981 Unspecified Local Vulnerability
35697 Oracle E-Business Suite CVE-2009-1983 Remote Oracle iStore Vulnerability
35694 Oracle PeopleSoft CVE-2009-1989 Remote PeopleSoft Enterprise FMS Vulnerability
35689 Oracle Database CVE-2009-1969 Remote Auditing Vulnerability
35684 Oracle Database CVE-2009-1020 Network Foundation Remote Vulnerability
35688 Oracle Application Server CVE-2009-1976 Remote HTTP Server Vulnerability
35690 Oracle E-Business Suite CVE-2009-1984 Application Install Local Vulnerability
35692 Oracle Config Management CVE-2009-1967 Remote Unspecified Vulnerability
35686 Oracle E-Business Suite CVE-2009-1980 Remote Vulnerability
35682 Oracle Database CVE-2009-1015 Remote Core RDBMS Vulnerability
35680 Oracle Database CVE-2009-1019 Remote Network Authentication Vulnerability
35687 Oracle Database CVE-2009-1973 Remote Virtual Private Database Vulnerability
35677 Oracle Database CVE-2009-1963 Remote Network Foundation Vulnerability
35685 Oracle Advanced Replication CVE-2009-1021 Remote Unspecified Vulnerability
35681 Oracle Database CVE-2009-1968 Remote Secure Enterprise Search Vulnerability
35678 Oracle Secure Backup CVE-2009-1978 Remote Oracle Secure Backup Vulnerability
35683 Oracle Database CVE-2009-1970 Remote Listener Vulnerability
34800 Jetty Cross Site Scripting and Information Disclosure Vulnerabilities
35672 Oracle Secure Backup CVE-2009-1977 Remote Oracle Secure Backup Vulnerability
35679 Oracle Database CVE-2009-0987 Remote Upgrade Vulnerability
35676 Oracle Config Management CVE-2009-1966 Unspecified Security Vulnerability
35674 Oracle WebLogic Server CVE-2009-1974 Remote Vulnerability
35673 Oracle Weblogic Server CVE-2009-1975 Remote Vulnerability
35696 Oracle PeopleSoft Enterprise HRMS eProfile Manager CVE-2009-1988 Remote Vulnerability
35695 Oracle E-Business Suite CVE-2009-1986 Remote Oracle Applications Manager Vulnerability
35693 Oracle E-Business Suite CVE-2009-1982 Remote Oracle Applications Framework Vulnerability
35691 Oracle PeopleSoft Enterprise PeopleTools CVE-2009-1987 Unspecified Remote Vulnerability
35671 IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
34240 Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
Exploit / POC
RETIRED: Oracle July 2009 Critical Patch Update Multiple Vulnerabilities
Some of these issues may not require specific exploit code and may be trivial to exploit.
Some of these issues may not require specific exploit code and may be trivial to exploit.
Solution / Fix
RETIRED: Oracle July 2009 Critical Patch Update Multiple Vulnerabilities
Solution:
Vendor updates are available. Please see the referenced advisory for details.
Solution:
Vendor updates are available. Please see the referenced advisory for details.
References
RETIRED: Oracle July 2009 Critical Patch Update Multiple Vulnerabilities
References:
References:
- Oracle Homepage (Oracle)
- Oracle Critical Patch Update Advisory - July 2009 (Oracle)