RETIRED: Oracle October 2009 Critical Patch Update Multiple Vulnerabilities

BID:36711

Info

RETIRED: Oracle October 2009 Critical Patch Update Multiple Vulnerabilities

Bugtraq ID: 36711
Class: Unknown
CVE:
Remote: Yes
Local: Yes
Published: Oct 15 2009 12:00AM
Updated: Oct 21 2009 12:48AM
Credit: Yaniv Azaria of Imperva, Inc.; Cesar Cerrudo of Argeniss; Deniz Cevik of Intellect; Joxean Koret; Joxean Koret of iSIGHT Partners Global Vulnerability Partnership; Alexander Kornbrust of Red Database Security; David Litchfield of NGS Software; Ryan Permeh
Vulnerable: Oracle Weblogic Server 9.3 MP3
Oracle Weblogic Server 9.2 MP3
Oracle Weblogic Server 9.2 MP2
Oracle Weblogic Server 9.2 MP1
Oracle Weblogic Server 9.2
Oracle Weblogic Server 9.1 GA
Oracle Weblogic Server 9.1
Oracle Weblogic Server 9.0 GA
Oracle Weblogic Server 8.1 SP6
Oracle Weblogic Server 8.1 MP6
Oracle Weblogic Server 8.1 MP4
Oracle Weblogic Server 8.1
Oracle Weblogic Server 7.0 MP5
Oracle Weblogic Server 7.0 MP4
Oracle Weblogic Server 7.0 MP2
Oracle Weblogic Server 7.0
Oracle Weblogic Server 10.3
Oracle Weblogic Server 10.1
Oracle Weblogic Server 10.0 MP1
Oracle Weblogic Server 10
Oracle PeopleSoft Enterprise Portal 8.49
Oracle PeopleSoft Enterprise PeopleTools 8.49
Oracle PeopleSoft Enterprise Human Capital Management 9.0
Oracle PeopleSoft Enterprise Human Capital Management 8.9
Oracle Oracle9i Standard Edition 9.2 .8DV
Oracle Oracle9i Standard Edition 9.2 .8
Oracle Oracle9i Personal Edition 9.2 .8DV
Oracle Oracle9i Personal Edition 9.2 .8
Oracle Oracle9i Enterprise Edition 9.2 .8DV
Oracle Oracle9i Enterprise Edition 9.2 .8.0
Oracle Oracle11g Standard Edition 11.1 .7
Oracle Oracle11g Enterprise Edition 11.1.0.7
Oracle Oracle10g Standard Edition 10.2 .3
Oracle Oracle10g Standard Edition 10.1 .0.5
Oracle Oracle10g Standard Edition 10.2.0.4
Oracle Oracle10g Personal Edition 10.2 .3
Oracle Oracle10g Personal Edition 10.1 .5
Oracle Oracle10g Personal Edition 10.2.0.4
Oracle Oracle10g Enterprise Edition 10.2 .3
Oracle Oracle10g Enterprise Edition 10.1 .5
Oracle Oracle10g Enterprise Edition 10.1 .5
Oracle Oracle10g Enterprise Edition 10.2.0.4
Oracle Oracle10g Application Server 10.1.3 .5.0
Oracle Oracle10g Application Server 10.1.3 .4.0
Oracle Oracle10g Application Server 10.1.2.3.0
Oracle JRockit R27.6.4
Oracle JRockit R27.6.3
Oracle JRockit R27.6.2
Oracle JRockit R27.6.0-50 1.5.0 15
Oracle JRockit R27.6.0
Oracle JD Edwards Tools 8.98
Oracle E-Business Suite 12 12.1
Oracle E-Business Suite 11i 11.5.10.2
Oracle E-Business Suite 12.0.6
Oracle Communications Order and Service Management 6.3.1
Oracle Communications Order and Service Management 6.3
Oracle Communications Order and Service Management 6.2
Oracle Communications Order and Service Management 2.8
Oracle Business Intelligence Enterprise Edition 10.1.3 .4.1
Oracle Business Intelligence Enterprise Edition 10.1.3 .4.0
Oracle AutoVue 19.3
Oracle Application Server 10g 10.1.2
Oracle Application Server 10.1.2.3
Oracle Agile Engineering Data Management 6.1
BEA Systems WebLogic Portal 8.1 SP6
BEA Systems WebLogic Portal 8.1 SP5
BEA Systems WebLogic Portal 8.1 SP4
BEA Systems WebLogic Portal 8.1 SP3
BEA Systems WebLogic Portal 8.1 SP2
BEA Systems WebLogic Portal 8.1 SP1
BEA Systems WebLogic Portal 8.1
BEA Systems WebLogic Portal 9.2 MP3
BEA Systems WebLogic Portal 9.2
BEA Systems WebLogic Portal 10.3
BEA Systems WebLogic Portal 10.2.MP1
BEA Systems WebLogic Portal 10.2
BEA Systems WebLogic Portal 10.0 MP1
BEA Systems WebLogic Portal 10.0
Not Vulnerable:

Discussion

RETIRED: Oracle October 2009 Critical Patch Update Multiple Vulnerabilities

Oracle has released the October 2009 Critical Patch Update that addresses 38 new vulnerabilities.

The following individual records now exist to better document these issues:

36771 Oracle JD Edwards EnterpriseOne CVE-2009-3406 JD Edwards Tools Unspecified Vulnerability
36773 Oracle PeopleSoft PeopleTools & Enterprise Portal CVE-2009-3404 Remote Vulnerability
36760 Oracle Database CVE-2009-1965 Remote Net Foundation Layer Vulnerability
36768 Oracle E-Business Suite CVE-2009-3401 Local Oracle Applications Technology Stack Vulnerability
36774 Oracle WebLogic Portal CVE-2009-2002 Remote Unspecified Vulnerability
36772 Oracle JD Edwards Tools CVE-2009-3405 Remote JD Edwards Tools Vulnerability
36749 Oracle Business Intelligence Enterprise Edition CVE-2009-1990 Vulnerability
36770 Oracle Agile Engineering Data Management CVE-2009-3392 Remote Vulnerability
36769 Oracle Weblogic Server CVE-2009-3399 Remote WebLogic Server Vulnerability
36767 Oracle E-Business Suite CVE-2009-3400 Oracle Advanced Benefits Unspecified Vulnerability
36766 Oracle WebLogic Server CVE-2009-3396 Remote WebLogic Server Vulnerability
36765 Oracle Database CVE-2009-1018 Workspace Manager Unspecified Vulnerability
36763 Oracle E-Business Suite CVE-2009-3408 Remote Oracle Application Object Library Vulnerability
36758 Oracle Database CVE-2009-1972 Remote Auditing Vulnerability
36764 Oracle E-Business Suite CVE-2009-3402 Remote Oracle Applications Framework Vulnerability
36754 Oracle Database CVE-2009-1971 Remote Data Pump Vulnerability
36762 Oracle E-Business Suite CVE-2009-3397 Remote Oracle Application Object Library Vulnerability
36761 Oracle E-Business Suite CVE-2009-3395 Remote AutoVue Vulnerability
36757 Oracle E-Business Suite CVE-2009-3393 Remote Oracle Application Object Library Vulnerability
36750 Oracle Database CVE-2009-1007 Remote Data Mining Vulnerability
36759 Oracle Database CVE-2009-1993 Application Express Unspecified Vulnerability
36756 Oracle Database CVE-2009-2000 Remote Authentication Vulnerability
36755 Oracle Database CVE-2009-1964 Remote Workspace Manager Vulnerability
36747 Oracle Network Authentication CVE-2009-1979 Unspecified Security Vulnerability
36753 Oracle Application Server CVE-2009-3407 Remote Portal Vulnerability
36748 Oracle Database CVE-2009-1991 Remote Oracle Text Vulnerability
36752 Oracle Database CVE-2009-1995 Remote Advanced Queuing Vulnerability
36751 Oracle Database CVE-2009-1997 Remote Authentication Vulnerability
36745 Oracle Database CVE-2009-1985 Remote Network Authentication Vulnerability
36746 Oracle Business Intelligence Enterprise Edition CVE-2009-1999 Remote Vulnerability
36744 Oracle Database CVE-2009-1994 Remote Oracle Spatial Vulnerability
36742 Oracle Database CVE-2009-1992 Remote Core RDBMS Vulnerability
36743 Oracle Database CVE-2009-2001 Remote PL/SQL Vulnerability
36775 Oracle Communications Order and Service Management CVE-2009-1998 Remote Vulnerability
36776 Oracle PeopleSoft Enterprise Human Capital Management CVE-2009-3409 Remote Vulnerability
35939 Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability
35943 Sun Java Runtime Environment Proxy Mechanism Implementation Privilege Escalation Vulnerabilities
35942 Sun Java Runtime Environment JPEG Image Handling Integer Overflow Vulnerability
35944 Sun Java Runtime Environment Unpack200 JAR Unpacking Utility Integer Overflow Vulnerability
35946 JNLPAppletLauncher Arbitrary File Creation Vulnerability
35671 IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
35958 Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability

Exploit / POC

RETIRED: Oracle October 2009 Critical Patch Update Multiple Vulnerabilities

Some of these issues may not require specific exploit code and may be trivial to exploit.

Solution / Fix

RETIRED: Oracle October 2009 Critical Patch Update Multiple Vulnerabilities

Solution:
Oracle has released CPUOct2009 (Critical Patch Update October 2009) to address these issues. Contact the vendor for details on obtaining and applying the appropriate updates.

References

RETIRED: Oracle October 2009 Critical Patch Update Multiple Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report