Oracle Database Text Component 'ctxsys.drvxtabc.create_tables' Remote SQL Injection Vulnerability
BID:36748
Info
Oracle Database Text Component 'ctxsys.drvxtabc.create_tables' Remote SQL Injection Vulnerability
| Bugtraq ID: | 36748 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-1991 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 20 2009 12:00AM |
| Updated: | Dec 02 2009 03:44PM |
| Credit: | Oracle |
| Vulnerable: |
Oracle Oracle9i Standard Edition 9.2 .8DV Oracle Oracle9i Standard Edition 9.2 .8 Oracle Oracle9i Personal Edition 9.2 .8DV Oracle Oracle9i Personal Edition 9.2 .8 Oracle Oracle9i Enterprise Edition 9.2 .8DV Oracle Oracle9i Enterprise Edition 9.2 .8.0 Oracle Oracle10g Standard Edition 10.1 .0.5 Oracle Oracle10g Standard Edition 10.2.0.4 Oracle Oracle10g Personal Edition 10.1 .5 Oracle Oracle10g Personal Edition 10.2.0.4 Oracle Oracle10g Enterprise Edition 10.1 .5 Oracle Oracle10g Enterprise Edition 10.2.0.4 |
| Not Vulnerable: | |
Discussion
Oracle Database Text Component 'ctxsys.drvxtabc.create_tables' Remote SQL Injection Vulnerability
Oracle Database is prone to an SQL-injection vulnerability in Oracle Text.
The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Execute on CTXSYS.DRVXTABC' privileges.
Exploiting this issue could allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This vulnerability affects the following supported versions:
9.2.0.8
9.2.0.8DV
10.1.0.5
10.2.0.4
Oracle Database is prone to an SQL-injection vulnerability in Oracle Text.
The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Execute on CTXSYS.DRVXTABC' privileges.
Exploiting this issue could allow the attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This vulnerability affects the following supported versions:
9.2.0.8
9.2.0.8DV
10.1.0.5
10.2.0.4
Exploit / POC
Oracle Database Text Component 'ctxsys.drvxtabc.create_tables' Remote SQL Injection Vulnerability
Exploits are available.
Note that some of these exploits may not work as expected. Please see the referenced note from the author for more information.
Exploits are available.
Note that some of these exploits may not work as expected. Please see the referenced note from the author for more information.
Solution / Fix
Oracle Database Text Component 'ctxsys.drvxtabc.create_tables' Remote SQL Injection Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for details.
Solution:
Vendor updates are available. Please contact the vendor for details.
References
Oracle Database Text Component 'ctxsys.drvxtabc.create_tables' Remote SQL Injection Vulnerability
References:
References:
- [DSECRG-09-010] Oracle Database 10G CTXSYS.DRVXTABX - PLSQL Injection (Alexandr Polyakov)
- Oracle exploit for CTXSYS.DRVXTABC.CREATE_TABLES and others (Andrea Purificato
) - Re: [rejected] Oracle exploit for CTXSYS.DRVXTABC.CREATE_TABL (Andrea Purificato)
- Oracle Critical Patch Update Advisory - October 2009 (Oracle)