Multiple Vulnerabilities in Oracle Database Server

Oracle Database 9i and 10g are vulnerable to PL/SQL injection and an unchecked buffer.

ITPro Today

January 17, 2005

1 Min Read
ITPro Today logo



Reported January 18,2005, byNGSSoftware

VERSIONS AFFECTED

        All releases of versions 10g and 9i

DESCRIPTION

Multiple vulnerabilities have been discovered in Oracle DatabaseServer. Thevulnerabilities include "PL/SQL" injection and an unchecked buffer,which could allow an overflow to occur. The vulnerabilities could allowusers to gain adminstrator privileges on an affect server.


VENDOR RESPONSE

Oracle has issued patches to correct these problems which can beobtained at the company's MetaLinkWeb site.

CREDIT
Discovered by Next Generation Security Software

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like