Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:ORACLE:DBMS:EXPORT-PRIV

Severity

High

Recommended

No

Recommended Action

Drop

Category

DB

Keywords

Oracle DBMS_EXPORT_EXTENSION Package Privilege Escalation

Release Date

2006/05/30

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: Oracle DBMS_EXPORT_EXTENSION Package Privilege Escalation


This signature detects attempts to exploit a known vulnerability against Oracle Database Server. A successful attack can lead to privilege escalation.

Extended Description

Oracle has released a Critical Patch Update advisory for April 2006 to address multiple vulnerabilities in multiple Oracle products. This Critical Patch Update addresses the vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by the issues as well. The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to exploit some of the issues, but other issues do not require any authorization. The most severe of these vulnerabilities could possibly expose affected computers to complete compromise. This record will be updated and split into individual BIDs for each issue as further information is disclosed.

Affected Products

  • HP HP-UX 11.11.0
  • HP HP-UX 11.23.0
  • HP HP-UX B.11.11
  • HP HP-UX B.11.23
  • Oracle Collaboration Suite Release 1 10.1.1
  • Oracle Collaboration Suite Release 1 10.1.2
  • Oracle Collaboration Suite Release 1 10.1.2 .1
  • Oracle Collaboration Suite Release 2 9.0.4 .2
  • Oracle Developer Suite 9.0.4 .2
  • Oracle E-Business Suite 11.0.0
  • Oracle E-Business Suite 11i 11.5.1
  • Oracle E-Business Suite 11i 11.5.10
  • Oracle E-Business Suite 11i 11.5.10 CU2
  • Oracle E-Business Suite 11i 11.5.2
  • Oracle E-Business Suite 11i 11.5.3
  • Oracle E-Business Suite 11i 11.5.4
  • Oracle E-Business Suite 11i 11.5.5
  • Oracle E-Business Suite 11i 11.5.6
  • Oracle E-Business Suite 11i 11.5.7
  • Oracle E-Business Suite 11i 11.5.8
  • Oracle E-Business Suite 11i 11.5.9
  • Oracle Enterprise Manager Grid Control 10g 10.1.0 .3
  • Oracle Enterprise Manager Grid Control 10g 10.1.0 .4
  • Oracle Enterprise Manager Grid Control 10g 10.2.0 .1
  • Oracle JD Edwards EnterpriseOne 8.95
  • Oracle JD Edwards EnterpriseOne 8.95.0 B1
  • Oracle JD Edwards EnterpriseOne 8.95.0 F1
  • Oracle JD Edwards EnterpriseOne 8.95.J1
  • Oracle Oracle10g Application Server 10.1.2
  • Oracle Oracle10g Application Server 10.1.2 .0.1
  • Oracle Oracle10g Application Server 10.1.2 .0.2
  • Oracle Oracle10g Application Server 10.1.2 .1.0
  • Oracle Oracle10g Application Server 10.1.3 .0.0
  • Oracle Oracle10g Application Server 9.0.4 .1
  • Oracle Oracle10g Application Server 9.0.4 .2
  • Oracle Oracle10g Enterprise Edition 10.1.0 .0.3
  • Oracle Oracle10g Enterprise Edition 10.2.0 .1
  • Oracle Oracle10g Enterprise Edition 10.2.0 .2
  • Oracle Oracle10g Personal Edition 10.1.0 .0.3
  • Oracle Oracle10g Personal Edition 10.2.0 .1
  • Oracle Oracle10g Personal Edition 10.2.0 .2
  • Oracle Oracle10g Standard Edition 10.1.0 .0.3
  • Oracle Oracle10g Standard Edition 10.1.0 .4.2
  • Oracle Oracle10g Standard Edition 10.2.0.1
  • Oracle Oracle10g Standard Edition 10.2.0 .2
  • Oracle Oracle8 8.0.6
  • Oracle Oracle8 8.0.6 .3
  • Oracle Oracle8i Enterprise Edition 8.1.7.4.0
  • Oracle Oracle8i Standard Edition 8.1.7 .4
  • Oracle Oracle 9i Application Server Release 1 1.0.2 .2
  • Oracle Oracle9i Enterprise Edition 9.0.1 .4
  • Oracle Oracle9i Enterprise Edition 9.0.1 .5
  • Oracle Oracle9i Enterprise Edition 9.0.1 .5 FIPS
  • Oracle Oracle9i Enterprise Edition 9.2.0 .0.5
  • Oracle Oracle9i Enterprise Edition 9.2.0.6.0
  • Oracle Oracle9i Enterprise Edition 9.2.0.7.0
  • Oracle Oracle9i Personal Edition 9.2.0 .0.5
  • Oracle Oracle9i Personal Edition 9.2.0 .6
  • Oracle Oracle9i Personal Edition 9.2.0 .7
  • Oracle Oracle9i Standard Edition 9.2.0 .0.5
  • Oracle Oracle9i Standard Edition 9.2.0 .6
  • Oracle Oracle9i Standard Edition 9.2.0 .7
  • Oracle PeopleSoft Enterprise Tools 8.46.12
  • Oracle PeopleSoft Enterprise Tools 8.46 GA
  • Oracle PeopleSoft Enterprise Tools 8.47.01
  • Oracle PeopleSoft Enterprise Tools 8.47.02
  • Oracle PeopleSoft Enterprise Tools 8.47.03
  • Oracle PeopleSoft Enterprise Tools 8.47.04
  • Oracle PeopleSoft Enterprise Tools 8.47 GA
  • Oracle Pharmaceutical Applications 4.5.0
  • Oracle Pharmaceutical Applications 4.5.1
  • Oracle Pharmaceutical Applications 4.5.2
  • Oracle Workflow 11.5.1
  • Oracle Workflow 11.5.9 .5

References

  • BugTraq: 17590
  • CVE: CVE-2006-1867
  • URL: http://www.frsirt.com/english/advisories/2006/1397
  • URL: http://www.oracle.com/technology/deploy/security/pdf/cpuapr2006.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out