Oracle.SYS.LT.ROLLBACKWORKSPACE.SQL.Injection

description-logoDescription

This indicates an exploit attempt against the sql injection vulnerability in Oracle database system.
The vulnerability lies in the SYS.LT.ROLLBACKWORKSPACE procedure of Oracle database. A specially crafted parameters could allow attacker to execute SQL statements with SYS or WMSYS privileges.

affected-products-logoAffected Products

Oracle 10g R1

Impact logoImpact

Privilege Escalation: Remote attackers can leverage their privilege on the vulnerable systems.

recomended-action-logoRecommended Actions

Apply the patch from vendor's website.
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2009.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)