Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

DB:ORACLE:DBMS:METADATA-UNSAFE

Severity

High

Recommended

No

Recommended Action

Drop

Category

DB

Keywords

Oracle DBMS_METADATA Unsafe Command

Release Date

2005/05/03

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

DB: Oracle DBMS_METADATA Unsafe Command


This signature detects attempts to exploit a known vulnerability against SYS.DBMS_METADATA package bundled with Oracle Database Server. Attackers can use vulnerable programs (functions and stored procedures) to exploit these functions and inject arbitrary data.

Extended Description

Oracle Database Server is prone to SQL injection in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET standard procedure. This may permit an attacker who can influence the invocation parameters of the stored procedure to compromise the database. This issue was originally disclosed in the "Oracle Critical Patch Update - April 2005" advisory. BID 13139 Oracle Multiple Vulnerabilities describes the issues covered in the Oracle advisory. There is insufficient information at this point in time to associate this vulnerability with an identifier from the Oracle advisory.

Affected Products

  • Oracle Oracle10g Enterprise Edition 10.1.0 .0.2
  • Oracle Oracle10g Enterprise Edition 10.1.0 .0.3
  • Oracle Oracle10g Enterprise Edition 10.1.0 .0.3.1
  • Oracle Oracle10g Enterprise Edition 10.1.0 .0.4
  • Oracle Oracle10g Personal Edition 10.1.0 .0.2
  • Oracle Oracle10g Personal Edition 10.1.0 .0.3
  • Oracle Oracle10g Personal Edition 10.1.0 .0.3.1
  • Oracle Oracle10g Personal Edition 10.1.0 .0.4
  • Oracle Oracle10g Standard Edition 10.1.0 .0.2
  • Oracle Oracle10g Standard Edition 10.1.0 .0.3
  • Oracle Oracle10g Standard Edition 10.1.0 .0.3.1
  • Oracle Oracle10g Standard Edition 10.1.0 .0.4

References

  • BugTraq: 13238
  • BugTraq: 13234
  • CVE: CVE-2005-1197
  • URL: http://www.securiteam.com/securitynews/5SP0M0AFGI.html
  • URL: http://www.oracle.com/technology/deploy/security/pdf/cpuapr2005.pdf

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out