CVE-2006-0259
published 2006-01-18CVE-2006-0259: Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and…
critical10CVSS 3.1
AVNACLAuNCCICAC
Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
GHSA
GHSA-63c4-h6jq-3fj3: SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrar
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2006-0551 [CRITICAL] GHSA-63c4-h6jq-3fj3: SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrar
SQL injection vulnerability in the Data Pump Metadata API in Oracle Database 10g and possibly earlier might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB06 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0259 or, if it is DB05, subsumed by CVE-2006-0260.
GHSA
GHSA-rmm4-fh7h-3246: Multiple unspecified vulnerabilities in Oracle Database server 10
ghsa_unreviewed·2022-05-01
CVE-2006-0259 [HIGH] GHSA-rmm4-fh7h-3246: Multiple unspecified vulnerabilities in Oracle Database server 10
Multiple unspecified vulnerabilities in Oracle Database server 10.1.0.5 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) DB04 and (2) DB06 in the (a) Data Pump component; (3) DB10 in the (b) Net Listener component; and (4) DB16 in the (c) Oracle Text component. NOTE: details are unavailable from Oracle, but they have not publicly disputed a claim by a reliable independent researcher that states that DB06 is SQL injection in the GENERATE_JOB_NAME, GET_WORKERSTATUSLIST1010, GET_PARAMVALUES1010, GET_DUMPFILESET1010, GET_JOBSTATUS1010, ATTACH, and ESTABLISH_REMOTE_CONTEXT functions in DBMS_DATAPUMP.
GHSA
GHSA-ff55-4qfm-2hmv: SQL injection vulnerability in the SYS
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2006-0549 [CRITICAL] GHSA-ff55-4qfm-2hmv: SQL injection vulnerability in the SYS
SQL injection vulnerability in the SYS.DBMS_METADATA_UTIL package in Oracle Database 10g, and possibly earlier versions, might allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by Oracle. It is possible that this is the same issue as Oracle Vuln# DB05 from the January 2006 CPU, in which case this would be subsumed by CVE-2006-0260. However, there are some inconsistencies that make this unclear, and there is also a possibility that this is related to DB06, which is subsumed by CVE-2006-0259.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/18493http://secunia.com/advisories/18608http://securitytracker.com/id?1015499http://www.kb.cert.org/vuls/id/545804http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.htmlhttp://www.osvdb.org/22544http://www.securityfocus.com/bid/16287http://www.vupen.com/english/advisories/2006/0243http://www.vupen.com/english/advisories/2006/0323https://exchange.xforce.ibmcloud.com/vulnerabilities/24321http://secunia.com/advisories/18493http://secunia.com/advisories/18608http://securitytracker.com/id?1015499http://www.kb.cert.org/vuls/id/545804http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.htmlhttp://www.osvdb.org/22544http://www.securityfocus.com/bid/16287http://www.vupen.com/english/advisories/2006/0243http://www.vupen.com/english/advisories/2006/0323https://exchange.xforce.ibmcloud.com/vulnerabilities/24321
2006-01-18
Published