Oracle Database Server 'Execute on DBMS_SYS_SQL' Remote Database Vault Vulnerability
29 Mar. 2012
Summary
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL.
Vulnerable Systems:
* Oracle11g Standard Edition 11.1 .7
* Oracle11g Standard Edition 11.2.0.1.0
* Oracle11g Standard Edition 11.2.0.1 R2
* Oracle11g Standard Edition 11.1.0.7 R1
* Oracle11g Enterprise Edition 11.2.0.1.0
* Oracle11g Enterprise Edition 11.2.0.1 R2
* Oracle11g Enterprise Edition 11.1.0.7 R1
* Oracle11g Enterprise Edition 11.1.0.7
* Oracle10g Standard Edition 10.2 .5
* Oracle10g Standard Edition 10.2 .3 R2
* Oracle10g Standard Edition 10.2 .3
* Oracle10g Standard Edition 10.2.0.4 R2
* Oracle10g Standard Edition 10.2.0.4
* Oracle10g Personal Edition 10.2 .5
* Oracle10g Personal Edition 10.2 .3 R2
* Oracle10g Personal Edition 10.2 .3
* Oracle10g Personal Edition 10.2.0.4 R2
* Oracle10g Personal Edition 10.2.0.4
* Oracle10g Enterprise Edition 10.2 .5
* Oracle10g Enterprise Edition 10.2 .3 R2
* Oracle10g Enterprise Edition 10.2 .3
* Oracle10g Enterprise Edition 10.2.0.4 R2
* Oracle10g Enterprise Edition 10.2.0.4
Oracle Database Server is prone to a remote vulnerability in Database Vault.
The vulnerability can be exploited over the 'Oracle Net' protocol. For an exploit to succeed, the attacker must have 'Execute on DBMS_SYS_SQL' privileges.
Vendor Status:
Oracle as issued an update for this vulnerablity