CVE-2007-3855
published 2007-07-18CVE-2007-3855: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an…
PriorityP342medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EXPLOIT
EPSS
15.82%
96.5th percentile
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to have an unknown impact via (1) SYS.DBMS_DRS in the DataGuard component (DB03), (2) SYS.DBMS_STANDARD in the PL/SQL component (DB10), (3) MDSYS.RTREE_IDX in the Spatial component (DB16), and (4) SQL Compiler (DB17). NOTE: a reliable researcher claims that DB17 is for using Views to perform unauthorized insert, update, or delete actions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Oracle 9i/10g - Evil Views Change Passwords
exploitdb·2007-07-19·CVSS 6.5
CVE-2007-3855 [MEDIUM] Oracle 9i/10g - Evil Views Change Passwords
Oracle 9i/10g - Evil Views Change Passwords
---
--
-- bunkerview.sql
--
-- Oracle 9i/10g - evil view exploit (CVE-2007-3855)
-- Uses evil view to perform unauthorized password update
--
-- by Andrea "bunker" Purificato - http://rawlab.mindcreations.com
-- 37F1 A7A1 BB94 89DB A920 3105 9F74 7349 AF4C BFA2
--
-- This code should be used only for LEGAL purpose!
-- ...and remember: use Oracle at your own risk ;-)
--
-- Thanks to security researchers all around the world...
-- Smarties rules (they know what I mean)! ;-D
--
--
-- SQL> select * from user_sys_privs;
--
-- USERNAME PRIVILEGE ADM
-- ------------------------------ ---------------------------------------- ---
-- TEST CREATE VIEW NO
-- TEST CREATE SESSION NO
--
-- SQL> select password from sys.user$ where name='TEST';
--
-- PASSWORD
Exploit-DB
Oracle Database - SQL Compiler Views Unauthorized Manipulation
exploitdb·2007-07-12·CVSS 6.5
CVE-2007-3855 [MEDIUM] Oracle Database - SQL Compiler Views Unauthorized Manipulation
Oracle Database - SQL Compiler Views Unauthorized Manipulation
---
source: https://www.securityfocus.com/bid/24887/info
Oracle has released a Critical Patch Update advisory for July 2007 to address multiple vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by these issues as well.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to leverage some of the issues, but other issues do not require any authorization. The most severe of the vulnerabilities could possibly expose affected computers to complete compromise.
--
-- bunkerview.sql
--
-- Oracle 9i/10g - evil view exploit (CVE-2007-3855)
-- Uses evil view to perform unau
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143http://rawlab.mindcreations.com/codes/exp/oracle/bunkerview.sqlhttp://secunia.com/advisories/26114http://secunia.com/advisories/26166http://securityreason.com/securityalert/2903http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdfhttp://www.oracle.com/technetwork/topics/security/cpujul2007-087014.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_jul_2007.htmlhttp://www.red-database-security.com/advisory/oracle_view_vulnerability.htmlhttp://www.securityfocus.com/archive/1/473997/100/0/threadedhttp://www.securityfocus.com/archive/1/474326/100/0/threadedhttp://www.securitytracker.com/id?1018415http://www.us-cert.gov/cas/techalerts/TA07-200A.htmlhttp://www.vupen.com/english/advisories/2007/2562http://www.vupen.com/english/advisories/2007/2635https://exchange.xforce.ibmcloud.com/vulnerabilities/35490https://exchange.xforce.ibmcloud.com/vulnerabilities/35495http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c00727143http://rawlab.mindcreations.com/codes/exp/oracle/bunkerview.sqlhttp://secunia.com/advisories/26114http://secunia.com/advisories/26166http://securityreason.com/securityalert/2903http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_July_2007_Analysis.pdfhttp://www.oracle.com/technetwork/topics/security/cpujul2007-087014.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_jul_2007.htmlhttp://www.red-database-security.com/advisory/oracle_view_vulnerability.htmlhttp://www.securityfocus.com/archive/1/473997/100/0/threadedhttp://www.securityfocus.com/archive/1/474326/100/0/threadedhttp://www.securitytracker.com/id?1018415http://www.us-cert.gov/cas/techalerts/TA07-200A.htmlhttp://www.vupen.com/english/advisories/2007/2562http://www.vupen.com/english/advisories/2007/2635https://exchange.xforce.ibmcloud.com/vulnerabilities/35490https://exchange.xforce.ibmcloud.com/vulnerabilities/35495
2007-07-18
Published