Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:SQL:INJ:REMOTE-EXEC

Severity

Minor

Recommended

No

Category

HTTP

Keywords

Oracle Remote SQL Execution

Release Date

2005/03/02

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Oracle Remote SQL Execution


This signature detects attempts to use the UTL_FILE or UTL_HTTP packages that ship with Oracle. Attackers can use these packages to force an Oracle database server to execute malicious remote SQL queries.

Extended Description

It is reported that Oracle Database 10g and Oracle9i Database Server products contain multiple unspecified vulnerabilities. The reported vulnerabilities include SQL injection vulnerabilities and a buffer overflow issue. It is reported that the issues may be exploited by unprivileged users to gain DBA privileges or to execute arbitrary attacker-supplied code in the context of the affected database service. NGSSoftware has stated that further details will be released on 18th of April 2005 regarding the issues that are described in this BID. Please see the referenced message for more information.

Affected Products

  • Oracle oracle10g_application_server 10.1.0 .0.2
  • Oracle oracle10g_application_server 9.0.4 .0
  • Oracle oracle10g_enterprise_edition 10.1.0 .0.2
  • Oracle oracle10g_enterprise_edition 9.0.4 .0
  • Oracle oracle10g_personal_edition 10.1.0 .0.2
  • Oracle oracle10g_personal_edition 9.0.4 .0
  • Oracle oracle10g_standard_edition 10.1.0 .0.2
  • Oracle oracle10g_standard_edition 9.0.4 .0
  • Oracle oracle9i_application_server 1.0.2
  • Oracle oracle9i_application_server 1.0.2 .1s
  • Oracle oracle9i_application_server 1.0.2 .2
  • Oracle oracle9i_application_server 1.0.2 .2.2
  • Oracle oracle9i_application_server 9.0.2
  • Oracle oracle9i_application_server 9.0.2 .0.0
  • Oracle oracle9i_application_server 9.0.2 .0.1
  • Oracle oracle9i_application_server 9.0.2 .1
  • Oracle oracle9i_application_server 9.0.2 .2
  • Oracle oracle9i_application_server 9.0.2 .3
  • Oracle oracle9i_application_server 9.0.3
  • Oracle oracle9i_application_server 9.0.3 .1
  • Oracle oracle9i_application_server
  • Oracle oracle9i_client_edition 9.2.0 .0.1
  • Oracle oracle9i_client_edition 9.2.0 .0.2
  • Oracle oracle9i_developer_edition 9.0.4
  • Oracle oracle9i_enterprise_edition 8.1.7
  • Oracle oracle9i_enterprise_edition 9.0.0 .2.4
  • Oracle oracle9i_enterprise_edition 9.0.1
  • Oracle oracle9i_enterprise_edition 9.0.1 .4
  • Oracle oracle9i_enterprise_edition 9.0.1 .5
  • Oracle oracle9i_enterprise_edition 9.2.0 .0
  • Oracle oracle9i_enterprise_edition 9.2.0 .0.1
  • Oracle oracle9i_enterprise_edition 9.2.0 .0.3
  • Oracle oracle9i_enterprise_edition 9.2.0 .0.5
  • Oracle oracle9i_enterprise_edition 9.2.0.2
  • Oracle oracle9i_lite 5.0.0 .0.0.0
  • Oracle oracle9i_lite 5.0.0 .1.0.0
  • Oracle oracle9i_lite 5.0.0 .2.0.0
  • Oracle oracle9i_lite 5.0.0 .2.9.0
  • Oracle oracle9i_personal_edition 8.1.7
  • Oracle oracle9i_personal_edition 9.0.0 .2.4
  • Oracle oracle9i_personal_edition 9.0.1
  • Oracle oracle9i_personal_edition 9.0.1 .4
  • Oracle oracle9i_personal_edition 9.0.1 .5
  • Oracle oracle9i_personal_edition 9.2.0
  • Oracle oracle9i_personal_edition 9.2.0 .0.1
  • Oracle oracle9i_personal_edition 9.2.0 .0.2
  • Oracle oracle9i_personal_edition 9.2.0 .0.3
  • Oracle oracle9i_personal_edition 9.2.0 .0.5
  • Oracle oracle9i_standard_edition 8.1.7
  • Oracle oracle9i_standard_edition 9.0.0
  • Oracle oracle9i_standard_edition 9.0.0 .2.4
  • Oracle oracle9i_standard_edition 9.0.1
  • Oracle oracle9i_standard_edition 9.0.1 .2
  • Oracle oracle9i_standard_edition 9.0.1 .3
  • Oracle oracle9i_standard_edition 9.0.1 .4
  • Oracle oracle9i_standard_edition 9.0.1 .5
  • Oracle oracle9i_standard_edition 9.0.2
  • Oracle oracle9i_standard_edition 9.2.0
  • Oracle oracle9i_standard_edition 9.2.0 .0.1
  • Oracle oracle9i_standard_edition 9.2.0 .0.2
  • Oracle oracle9i_standard_edition 9.2.0 .0.3
  • Oracle oracle9i_standard_edition 9.2.0 .0.5
  • Oracle oracle9i_standard_edition 9.2.0 .3

References

  • CVE: CVE-2005-0701
  • URL: http://security-papers.globint.com.ar/oracle_security/sql_injection_in_oracle.php
  • URL: http://www.argeniss.com/research/ARGENISS-ADV-030501.txt

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out