Oracle Database Server CVE-2012-1751 SQL Injection Vulnerability
BID:55950
Info
Oracle Database Server CVE-2012-1751 SQL Injection Vulnerability
| Bugtraq ID: | 55950 |
| Class: | Unknown |
| CVE: |
CVE-2012-1751 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2012 12:00AM |
| Updated: | Feb 21 2013 09:32PM |
| Credit: | Martin Rakhmanov of Application Security Inc. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle Database Server CVE-2012-1751 Remote Core RDBMS Vulnerability
Oracle Database Server is prone to a remote vulnerability in Core RDBMS.
The vulnerability can be exploited over the 'Oracle NET' protocol. For an exploit to succeed, the attacker must have 'Create session, create flashback archive' privileges.
This vulnerability affects the following supported versions:
11.1.0.7, 11.2.0.2, 11.2.0.3
Oracle Database Server is prone to a remote vulnerability in Core RDBMS.
The vulnerability can be exploited over the 'Oracle NET' protocol. For an exploit to succeed, the attacker must have 'Create session, create flashback archive' privileges.
This vulnerability affects the following supported versions:
11.1.0.7, 11.2.0.2, 11.2.0.3
Exploit / POC
Oracle Database Server CVE-2012-1751 SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Oracle Database Server CVE-2012-1751 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Oracle Database Server CVE-2012-1751 SQL Injection Vulnerability
References:
References: