Oracle Database Server is prone to a security-bypass vulnerability.
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0510
The original article can be found at: http://www.securityfocus.com/bid/53090
Vulnerable Systems:
* Oracle Oracle11g Standard Edition 11.1.0.7 R1
* Oracle Oracle11g Enterprise Edition 11.1.0.7 R1
* Oracle Oracle10g Standard Edition 10.2 .5
* Oracle Oracle10g Standard Edition 10.2 .3 R2
* Oracle Oracle10g Standard Edition 10.2.0.4 R2
* Oracle Oracle10g Personal Edition 10.2 .5
* Oracle Oracle10g Personal Edition 10.2 .3 R2
* Oracle Oracle10g Personal Edition 10.2.0.4 R2
* Oracle Oracle10g Enterprise Edition 10.2 .5
* Oracle Oracle10g Enterprise Edition 10.2 .3 R2
* Oracle Oracle10g Enterprise Edition 10.2.0.4 R2
An attacker may be able to exploit this issue to aid in brute-force attacks; other attacks may also be possible.
This vulnerability affects the following supported versions:
10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7
Vendor Status:
Oracle as issued an update for this vulnerablity
Patch Availability:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
CVE Information:
CVE-2012-0510
Disclosure Timeline:
2012-April-17 Rev 1. Initial Release
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by