Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2005-1197

Overview

Vulnerability Score 7.5 7.5
CVE Id CVE-2005-1197
Last Modified 05 Sep 2008 04:48:30
Published 02 May 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2005-1197

Summary

SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter.

Vulnerable Systems

Application

  • Oracle Database Server 10.1.0.2

  • Oracle Database Server 10.1.0.3

  • Oracle Database Server 10.1.0.3.1

  • Oracle Database Server 10.1.0.4


References

CERT - TA05-117A

CERT-VN - VU#948486

CONFIRM - http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf

BUGTRAQ - 20050418 [AppSecInc Team SHATTER Security Advisory] SQL Injection in CREATE_SCN_CHANGE_SET procedure


Last Updated: 27 May 2016 10:40:05