Oracle9iAS Portal Component SQL Injection Vulnerability
BID:8966
Info
Oracle9iAS Portal Component SQL Injection Vulnerability
| Bugtraq ID: | 8966 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2003 12:00AM |
| Updated: | Nov 03 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to David Litchfield of Generation Security Software Ltd. |
| Vulnerable: |
Oracle Oracle9i Application Server Portal 9.0.2 .3B Oracle Oracle9i Application Server Portal 9.0.2 .3A Oracle Oracle9i Application Server Portal 9.0.2 .3 Oracle Oracle9i Application Server Portal 3.0.9 .8.5 Oracle Oracle9i Application Server 9.0.2 .3 Oracle Oracle9i Application Server 9.0.2 .2 Oracle Oracle9i Application Server 9.0.2 .1 Oracle Oracle9i Application Server 9.0.2 .0.1 Oracle Oracle9i Application Server 9.0.2 .0.0 Oracle Oracle9i Application Server 9.0.2 |
| Not Vulnerable: | |
Discussion
Oracle9iAS Portal Component SQL Injection Vulnerability
It has been reported that Oracle9i application server is prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries through a URL. The cause of this problem is due to insufficient sanitization of user-supplied data. An attacker may be able to exploit this issue to influence SQL query logic.
Successful exploitation may disclose sensitive information about the underlying database to an attacker, which may be used to launch further attacks against a vulnerable system.
It has been reported that Oracle9i application server is prone to a SQL injection vulnerability that may allow a remote attacker to inject malicious SQL syntax into database queries through a URL. The cause of this problem is due to insufficient sanitization of user-supplied data. An attacker may be able to exploit this issue to influence SQL query logic.
Successful exploitation may disclose sensitive information about the underlying database to an attacker, which may be used to launch further attacks against a vulnerable system.
Exploit / POC
Oracle9iAS Portal Component SQL Injection Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Oracle9iAS Portal Component SQL Injection Vulnerability
Solution:
Oracle has released patch 3068980 for Portal Release 1 version 3.0.9.8.5 and patch 2852895 for Portal Release 2 version 9.0.2.3.0. Users may download that patches from Oracle metalink site listed in references.
Solution:
Oracle has released patch 3068980 for Portal Release 1 version 3.0.9.8.5 and patch 2852895 for Portal Release 2 version 9.0.2.3.0. Users may download that patches from Oracle metalink site listed in references.
References
Oracle9iAS Portal Component SQL Injection Vulnerability
References:
References:
- Oracle Security Alert #61 (Oracle)
- Oracle Support Metalink (Oracle)
- Multiple SQL Injection Vulnerabilities in Oracle Application Server 9i and RDBMS ("NGSSoftware Insight Security Research"
)