Oracle Enterprise Manager Grid Control CVE-2013-0373 SQL Injection Vulnerability
BID:57370
Info
Oracle Enterprise Manager Grid Control CVE-2013-0373 SQL Injection Vulnerability
| Bugtraq ID: | 57370 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-0373 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2013 12:00AM |
| Updated: | Feb 25 2013 05:43PM |
| Credit: | Esteban Martínez Fayó |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Oracle Enterprise Manager Grid Control CVE-2013-0373 SQL Injection Vulnerability
Oracle Enterprise Manager Grid Control is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This vulnerability affects the following supported versions:
EM Base Platform: 10.2.0.5, 11.1.0.1
EM DB Control: 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3
EM Plugin for DB: 12.1.0.1, 12.1.0.2
Oracle Enterprise Manager Grid Control is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This vulnerability affects the following supported versions:
EM Base Platform: 10.2.0.5, 11.1.0.1
EM DB Control: 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3
EM Plugin for DB: 12.1.0.1, 12.1.0.2
Exploit / POC
Oracle Enterprise Manager Grid Control CVE-2013-0373 SQL Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Oracle Enterprise Manager Grid Control CVE-2013-0373 SQL Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.