Vulnerabilities > CVE-2009-1021 - Unspecified vulnerability in Oracle Database Server
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN oracle
nessus
Summary
Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Nessus
NASL family | Databases |
NASL id | ORACLE_RDBMS_CPU_JUL_2009.NASL |
description | The remote Oracle database server is missing the July 2009 Critical Patch Update (CPU) and therefore is potentially affected by security issues in the following components : - Advanced Replication - Auditing - Config Management - Core RDBMS - Listener - Network Foundation - Secure Enterprise Search - Upgrade - Visual Private Database |
last seen | 2020-06-02 |
modified | 2011-11-16 |
plugin id | 56065 |
published | 2011-11-16 |
reporter | This script is Copyright (C) 2011-2020 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/56065 |
title | Oracle Database Multiple Vulnerabilities (July 2009 CPU) |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 35685 CVE ID: CVE-2009-1021 Oracle Database是一款商业性质大型数据库系统。 Oracle数据库Advanced Replication组件中的REPCAT_RPC.VALIDATE_REMOTE_RC()函数执行了可能受控的匿名PL/SQL。该函数取当前登录用户名为第一个参数,第二个参数VALIDATE_STRING直接放到了PLSQL的匿名块中并执行: ... ... SQL_CURSOR := DBMS_SQL.OPEN_CURSOR; DBMS_SQL.PARSE(SQL_CURSOR, 'BEGIN ' || ' :err := sys.dbms_repcat_validate.' || VALIDATE_STRING || '(:canon_gname);' || ' END;', DBMS_SQL.V7); DBMS_SQL.BIND_VARIABLE(SQL_CURSOR, 'err', ERR); DBMS_SQL.BIND_VARIABLE(SQL_CURSOR, 'canon_gname', CANON_GNAME); DUMMY := DBMS_SQL.EXECUTE(SQL_CURSOR); ... ... 这可能允许攻击者以提升的权限执行任意代码。 Oracle Database 9.2.0.8DV Oracle Database 9.2.0.8 Oracle Database 10.2.0.3 Oracle Database 10.1.0.5 厂商补丁: Oracle ------ Oracle已经为此发布了一个安全公告(cpujul2009)以及相应补丁: cpujul2009:Oracle Critical Patch Update Advisory - July 2009 链接:http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html |
id | SSV:12587 |
last seen | 2017-11-19 |
modified | 2009-11-07 |
published | 2009-11-07 |
reporter | Root |
source | https://www.seebug.org/vuldb/ssvid-12587 |
title | Oracle Advanced Replication组件REPCAT_RPC.VALIDATE_REMOTE_RC()函数权限提升漏洞 |
References
- http://osvdb.org/55886
- http://osvdb.org/55886
- http://secunia.com/advisories/35776
- http://secunia.com/advisories/35776
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.oracle.com/technetwork/topics/security/cpujul2009-091332.html
- http://www.securityfocus.com/bid/35685
- http://www.securityfocus.com/bid/35685
- http://www.securitytracker.com/id?1022560
- http://www.securitytracker.com/id?1022560
- http://www.vupen.com/english/advisories/2009/1900
- http://www.vupen.com/english/advisories/2009/1900
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51750
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51750