Vulnerabilities > CVE-2005-3206 - Remote Denial Of Service vulnerability in Oracle Database Server 9.0.2.4
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Databases |
NASL id | ORACLE_RDBMS_CPU_OCT_2005.NASL |
description | The remote Oracle database server is missing the October 2005 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components : - Change Data Capture - Data Guard Logical Standby - Data Pump Export - Database Scheduler - Export - Locale - Materialized Views - Objects Extension - Oracle HTTP Server - Oracle Intelligent Agent - Oracle Internet Directory - Oracle Label Security - Oracle Security Service - Oracle Single Sign-On - Oracle Spatial - Oracle Workflow Cartridge - PL/SQL - Programmatic Interface - Security - Workspace Manager |
last seen | 2020-06-02 |
modified | 2011-11-16 |
plugin id | 56050 |
published | 2011-11-16 |
reporter | This script is Copyright (C) 2011-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/56050 |
title | Oracle Database Multiple Vulnerabilities (October 2005 CPU) |
code |
|
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0176.html
- http://marc.info/?l=bugtraq&m=112870589127719&w=2
- http://secunia.com/advisories/15991/
- http://securityreason.com/securityalert/64
- http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html
- http://www.osvdb.org/20056
- http://www.red-database-security.com/advisory/oracle_isqlplus_shutdown.html
- http://www.securityfocus.com/bid/15032
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22544