Multiple Oracle Products contain critical vulnerabilities caused by a buffer overflow error in the EM Console when processing overly long HTTP requests.
Vulnerable Systems:
* Oracle Database 10g Release 2 version 10.2.0.3 and prior
* Oracle Database 10g Release 1 version 10.1.0.5 and prior
* Oracle Application Server 10gR2 version 10.1.2.3.0 and prior
* Oracle Identity Management 10g version 10.1.4.3 and prior
* Oracle Enterprise Manager Grid Control
The vulnerability is caused by a buffer overflow error in the EM Console when processing overly long HTTP requests, which could allow remote unauthenticated attackers to crash an affected service or execute arbitrary code via a malicious request.