Vulnerable Systems:
* Oracle Database Server 10.1.0.5,
* Oracle Database Server 10.2.0.3,
* Oracle Database Server 10.2.0.4;
* Oracle Enterprise Manager Grid Control 10.1.0.6
Oracle Database Server is prone to a remote vulnerability in Security Management. The vulnerability can be exploited over the 'HTTP' protocol. The 'Audit Administration' sub component is affected.
Vendor Status:
Oracle as issued an update for this vulnerablity
Disclosure Timeline:
2011-July-19 Rev 1. Initial Release
2011-July-19 Rev 2. Modified Credit Statement and modified Notes in Oracle Sun Products Risk Matrix.
2011-July-21 Rev 3. Pete Finnigan added to the In-Depth Credit Statement.
2011-July-22 Rev 4. Andy Davis added to the Credit Statement.
2011-August-2 Rev 5. Modified supported versions affected for PeopleSoft Enterprise PeopleTools for CVE-2011-2275, CVE-2011-2280 and CVE-2011-2274.
2011-August-19 Rev 6. Modified supported versions affected for PeopleSoft Enterprise PeopleTools and Oracle VM VirtualBox.
2011-December-15 Rev 7. Updated the CVSS score and note for CVE-2011-1511.