Oracle.DBMS.Cdc.Publish.SQL.Injection

description-logoDescription

This indicates a possible attack against an SQL-injection vulnerability in multiple products by Oracle.
The vulnerability is caused by improper sanitation of user input data which could lead to injection of arbitrary SQL code.

affected-products-logoAffected Products

Oracle Database 11g, versions 11.1.0.7 and 11.2.0.1
Oracle Database 10g Release 2, versions 10.2.0.3 and 10.2.0.4
Oracle Database 10g, version 10.1.0.5
Oracle Database 9i Release 2, versions 9.2.0.8 and 9.2.0.8DV
Oracle Application Server 10gR2, version 10.1.2.3.0
Oracle Identity Management 10g, version 10.1.4.0.1 and 10.1.4.3
Oracle Collaboration Suite 10g, version 10.1.2.4
Oracle E-Business Suite Release 12, versions 12.0.4, 12.0.5, 12.0.6, 12.1.1 and 12.1.2
Oracle E-Business Suite Release 11i, versions 11.5.10 and 11.5.10.2
Oracle Transportation Manager, versions 5.5.05.07, 5.5.06.00, and 6.0.03
Oracle Agile - Engineering Data Management, version 6.1.1.0
PeopleSoft Enterprise PeopleTools, versions 8.49 and 8.50
Oracle Communications Unified Inventory Management version 7.1
Oracle Clinical Remote Data Capture Option versions 4.5.3 and 4.6
Oracle Thesaurus Management System versions 4.5.2, 4.6 and 4.6.1
Oracle Retail Markdown Optimization version 13.1
Oracle Retail Place In-Season version 12.2
Oracle Retail Plan In-Season version 12.2
Oracle Sun Products Suite

Impact logoImpact

SQL injection could lead to system compromise.

recomended-action-logoRecommended Actions

Please apply the appropriate patch from the vendor:
http://support.oracle.com/CSP/main/article?cmd=show&type=NOT&id=985896.1

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)