 |
|
|
|
Многочисленные ошибки в Oracle (multiple bugs) дополнено с 19 апреля 2005 г. | | Опубликовано: |  | 23 декабря 2006 г. | | Источник: |  | BUGTRAQ | | SecurityVulns ID: |  | 4707 | | Тип: |  | удаленная | | Опасность: |  | 8/10 | | Описание: |  | SQL инъекции, DoS, модификация файлов, межсайтовый скриптинг, повышение привилегий, изменение параметров аудита. Передача пароля в открытом виде из JDeveloper в SQLPlus. Пароль JDeveloper хранится в открытом тексте в различных конфигурационных файлах формата XML. Пароль FormBuilder хранится в открытом тексте во временных файлах. Слабые разрешения на временные файлы. Перезапись и чтение любого файла в Oracle Reports. Выполнение любой команды через Oracle Forms и Oracle Reports. А также огромное количество других ошибок, многие из которых давно известны и до сих пор не исправлены, что позволяет говорить о нулевом уровне безопасности всех продуктов. Для обеспечения безопасности продуктов Oracle используйте разработки сторонних производителей. |
| Оригинальный текст |  | putosoft softputo, Oracle Applications/Portal 9i/10g Cross Site Scripting (23.12.2006) |
| |  | putosoft softputo, Oracle Portal 10g HTTP Response Splitting (20.12.2006) |
| |  | Kornbrust, Alexander, Modify Data via Inline Views (26.10.2006) |
| |  | Kornbrust, Alexander, Various Cross-Site-Scripting Vulnerabilities in Oracle Reports (26.10.2006) |
| |  | Kornbrust, Alexander, Cross-Site-Scripting Vulnerabilitiy in Oracle APEX NOTIFICATION_MSG (26.10.2006) |
| |  | Kornbrust, Alexander, Cross-Site-Scripting Vulnerability in Oracle APEX WWV_FLOW_ITEM_HELP (26.10.2006) |
| |  | Kornbrust, Alexander, SQL Injection in Oracle package MDSYS.SDO_LRS (26.10.2006) |
| |  | Kornbrust, Alexander, SQL Injection in package SYS.DBMS_CDC_IMPDP (26.10.2006) |
| |  | Kornbrust, Alexander, SQL Injection in package XDB.DBMS_XDBZ0 (26.10.2006) |
| |  | Kornbrust, Alexander, SQL Injection in package SYS.DBMS_SQLTUNE_INTERNAL (26.10.2006) |
| |  | putosoft softputo, Oracle 10g R2 and, probably, all previous versions (28.07.2006) |
| |  | Kornbrust, Alexander, Bypassing Oracle dbms_assert (28.07.2006) |
| |  | Kornbrust, Alexander, Oracle Database - SQL Injection in SYS.DBMS_UPGRADE [DB22] (24.07.2006) |
| |  | Kornbrust, Alexander, Oracle Database - SQL Injection in SYS.DBMS_STATS [DB21] (24.07.2006) |
| |  | Kornbrust, Alexander, Oracle Database - SQL Injection in SYS.DBMS_CDC_IMPDP [DB01] (24.07.2006) |
| |  | CERT, Oracle Database - SQL Injection in SYS.DBMS_CDC_IMPDP [DB01] (24.07.2006) |
| |  | CERT, US-CERT Technical Cyber Security Alert TA06-200A -- Oracle Products Contain Multiple Vulnerabilities (24.07.2006) |
| |  | Kornbrust, Alexander, Oracle Database - SQL Injection in SYS.KUPW$WORKER [DB03] (24.07.2006) |
| |  | David Litchfield, [Full-disclosure] Recent Oracle exploit is _actually_ an 0day with no patch (26.04.2006) |
| |  | c c, [Full-disclosure] [Argeniss] Oracle Database 10gR1 Buffer overflow in VERIFY_LOG procedure (20.04.2006) |
| |  | CERT, US-CERT Technical Cyber Security Alert TA06-109A -- Oracle Products Contain Multiple Vulnerabilities (20.04.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] SQL Injection in package SYS.DBMS_LOGMNR_SESSION (19.04.2006) |
| |  | NGSSoftware Insight Security Research, Multiple critical and high risk issues in Oracle's database server (19.04.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle read-only user can insert/update/delete data via specially crafted views (10.04.2006) |
| |  | David Litchfield, More on the workaround for the unpatched Oracle PLSQL Gateway flaw (03.02.2006) |
| |  | David Litchfield, The History of the Oracle PLSQL Gateway Flaw (03.02.2006) |
| |  | c c, [VulnWatch] [Argeniss] Oracle Database Buffer overflows vulnerabilities in public procedures of XDB.DBMS_XMLSCHEMA{_INT} (27.01.2006) |
| |  | David Litchfield, Workaround for unpatched Oracle PLSQL Gateway flaw (26.01.2006) |
| |  | CERT, US-CERT Technical Cyber Security Alert TA06-018A -- Oracle Products Contain Multiple Vulnerabilities (19.01.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT (18.01.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Database 10g Rel. 1 - SQL Injection in SYS.KUPV$FT_INT (18.01.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Database 10g Rel. 2 - Event 10053 logs TDE wallet password in cleartext (18.01.2006) |
| |  | Amichai Shulman, [Full-disclosure] Oracle DBMS - Access Control Bypass in Login (18.01.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Reports - Read parts of files via desname (fixed after 874 days) (18.01.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Reports - Overwrite any application server file via desname (fixed after 889 days) (18.01.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Reports - Read parts of files via customize(fixed after 875 days) (18.01.2006) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Database 10g Rel. 2- Transparent Data Encryption plaintext masterkey in SGA (18.01.2006) |
| |  | NGSSoftware Insight Security Research, Oracle DBMS_ASSERT and the October 2005 CPU (09.11.2005) |
| |  | NGSSoftware Insight Security Research, Oracle October 2005 CPU Problems (09.11.2005) |
| |  | snsadv_(at)_lac.co.jp, [SNS Advisory No.84] Oracle Application Server HTTP Response Splitting Vulnerability (22.10.2005) |
| |  | oracle_secalert_(at)_hushmail.com, [Full-disclosure] Exploit Oracle DB27 - CPU Octobre (20.10.2005) |
| |  | SPI Labs, Oracle 10g - emagent.exe Stack-Based Overflow (20.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Workflow CSS Vulnerability wf_route (20.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Workflow CSS Vulnerability wf_monitor (20.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Oracle Workflow CSS Vulnerability wf_monitor (20.10.2005) |
| |  | CERT, US-CERT Technical Cyber Security Alert TA05-292A -- Oracle Products Contain Multiple Vulnerabilities (20.10.2005) |
| |  | David Litchfield, Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers (07.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Cross-Site-Scripting Vulnerability in Oracle XMLDB (07.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Shutdown TNS Listener via Oracle iSQL*Plus (07.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Shutdown TNS Listener via Oracle Forms Servlet (07.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Plaintext Password Vulnerabilitiy during Installation of Oracle HTMLDB (07.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Cross-Site-Scripting Vulnerabilities in Oracle HTMLDB (07.10.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Cross-Site-Scripting Vulnerability in Oracle iSQL*Plus (07.10.2005) |
| |  | c c, [VulnWatch] [Full-disclosure] [Argeniss] Oracle 9R2 Unpatched vulnerability on CWM2_OLAP_AW_AWUTIL package (27.07.2005) |
| |  | c c, [Full-disclosure] [Argeniss] Oracle 9R2 Unpatched vulnerability on CWM2_OLAP_AW_AWUTIL package (23.07.2005) |
| |  | SECUNIA, [SA16121] Sun Management Center Oracle Listener Vulnerabilities (19.07.2005) |
| |  | Kornbrust, Alexander, Various Cross-Site-Scripting Vulnerabilities in Oracle Reports (19.07.2005) |
| |  | Kornbrust, Alexander, Read parts of any XML-file via customize parameter in Oracle Reports (19.07.2005) |
| |  | Kornbrust, Alexander, Read parts of any file via desformat in Oracle Reports (19.07.2005) |
| |  | Kornbrust, Alexander, Run any OS Command via unauthorized Oracle Reports (19.07.2005) |
| |  | Kornbrust, Alexander, Run any OS Command via unauthorized Oracle Forms (19.07.2005) |
| |  | Kornbrust, Alexander, Overwrite any file via desname in Oracle Reports (19.07.2005) |
| |  | Kornbrust, Alexander, [Full-disclosure] Silently fixed security bugs in Oracle Critical Patch Update July 2005 (15.07.2005) |
| |  | CERT, US-CERT Technical Cyber Security Alert TA05-194A -- Oracle Products Contain Multiple Vulnerabilities (14.07.2005) |
| |  | Kornbrust, Alexander, Oracle Forms Insecure Temporary File Handling (13.07.2005) |
| |  | Kornbrust, Alexander, Oracle Forms Builder Password in Temp Files (13.07.2005) |
| |  | Kornbrust, Alexander, Oracle JDeveloper Plaintext Passwords (13.07.2005) |
| |  | Kornbrust, Alexander, Name Oracle JDeveloper passes Plaintext Password (13.07.2005) |
| |  | David Litchfield, Problems with the Oracle Critical Patch Update for April 2005 (07.07.2005) |
| |  | Kornbrust, Alexander, Oracle 10g Exploit dbms_scheduler SESSION_USER issue (03.05.2005) |
| |  | Kornbrust, Alexander, Oracle Fine Grained Auditing Issue in Oracle 9i / 10g (03.05.2005) |
| |  | Kornbrust, Alexander, Webcache Client Requests bypasses OHS mod_access restrictions (28.04.2005) |
| |  | Kornbrust, Alexander, Append file in Oracle Webcache 9i (28.04.2005) |
| |  | Kornbrust, Alexander, Cross Site Scripting in Oracle Webcache 9i (28.04.2005) |
| |  | CERT, US-CERT Technical Cyber Security Alert TA05-117A -- Oracle Products Contain Multiple Vulnerabilities (28.04.2005) |
| |  | SECURITEAM, [EXPL] Multiple Exploit Codes for Oracle (interMedia, DBMS_CDC_SUBSCRIBE, DBMS_CDC_ISUBSCRIBE and DBMS_METADATA) (21.04.2005) |
| |  | SHATTER, [AppSecInc Team SHATTER Security Advisory] SQL Injection in ALTER_MANUALLOG_CHANGE_SOURCE procedure (19.04.2005) |
| |  | SHATTER, [AppSecInc Team SHATTER Security Advisory] Multiple SQL Injection vulnerabilities in DBMS_METADATA package (19.04.2005) |
| |  | SHATTER, [AppSecInc Team SHATTER Security Advisory] Denial of Service in Oracle interMedia (19.04.2005) |
| |  | SHATTER, [AppSecInc Team SHATTER Security Advisory] SQL Injection in CREATE_SCN_CHANGE_SET procedure (19.04.2005) |
| |  | SHATTER, [AppSecInc Team SHATTER Security Advisory] Multiple SQL Injection vulnerabilities in DBMS_CDC_SUBSCRIBE and DBMS_CDC_ISUBSCRIBE packages (19.04.2005) |
|
|
|
|
|
|
|
|