Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
|
|
|
|
|
|
|
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
|
|
|
|
Become a Partner and License Our Database or Notification Service
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Oracle Application Server Bugs Let Remote Users Access and Modify Data and Cause Denial of Service Conditions
|
|
SecurityTracker Alert ID: 1020494
|
|
SecurityTracker URL: http://securitytracker.com/id?1020494
|
|
CVE Reference: CVE-2008-2583
, CVE-2008-2589
, CVE-2008-2593
, CVE-2008-2594
, CVE-2008-2595
, CVE-2008-2609
, CVE-2008-2612
, CVE-2008-2614
(Links to External Site)
|
Date: Jul 15 2008
|
Impact: Denial of service via network, Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Oracle Security Advisory
|
Version(s): 10.1.3.3.0 and prior versions
|
Description: Several vulnerabilities were reported in Oracle Application Server. A remote user can access and modify data on the target system. A remote user can cause denial of service conditions.
A remote user can exploit several unspecified vulnerabilities to affect the confidentiality and integrity of data on the target system.
A
remote user can cause unspecified "partial" denial of service conditions.
No details were provided.
The Oracle Portal [CVE-2008-2583,
CVE-2008-2589, CVE-2008-2593, CVE-2008-2594, CVE-2008-2609], Oracle Internet Directory [CVE-2008-2595], Hyperion BI Plus [CVE-2008-2612],
Oracle HTTP Server [CVE-2008-2614] components are affected.
The following versions are affected:
- Oracle Application Server
10g Release 3 (10.1.3), versions 10.1.3.1.0, 10.1.3.3.0
- Oracle Application Server 10g Release 2 (10.1.2), versions 10.1.2.2.0,
10.1.2.3.0
- Oracle Application Server 10g (9.0.4), version 9.0.4.3
The following researchers reported these and other Oracle
vulnerabilities:
Flavio Casetta of Yocoya; Esteban Martinez Fayo of Application Security, Inc.; Johannes Greil of SEC Consult;
guyp of Sentrigo; Joxean Koret; Alexander Kornbrust of Red Database Security; Stephen Kost of Integrigy; Dave Lewis; David Litchfield
of NGS Software; Hirofumi Oka of JPCERT/CC Vulnerability Handling Team; Tanel Poder; Alexandr Polyakov of Digital Security; Andrea
Purificato; and Dave Wichers of Aspect Security.
|
Impact: A remote user can access and modify data on the target system.
A remote user can cause denial of service conditions.
|
Solution: The vendor has issued a fix, described in their July 2008 Critical Patch Update advisory.
The Oracle advisory is available at:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html
|
Vendor URL: www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), UNIX (Tru64), Windows (NT), Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 15 Jul 2008 18:41:29 -0400
Subject: Oracle Application Server
|
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html
CVE-2007-1359 Oracle HTTP Server HTTP None Yes 6.8 Network Medium None Partial Pa rtial Partial 10.1.2.3, 10.1.3.3
CVE-2008-2589 Oracle Portal HTTP None Yes 6.4 Network Low None Partial+ Partial+ None 9.0 .4.3, 10.1.2.2, 10.1.4.1
CVE-2008-2594 Oracle Portal HTTP None Yes 6.4 Network Low None Partial+ Partial+ None 10. 1.2.3, 10.1.4.2
CVE-2008-2609 Oracle Portal HTTP None Yes 6.4 Network Low None Partial+ Partial+ None 9.0 .4.3, 10.1.2.3, 10.1.4.2
CVE-2008-2595 Oracle Internet Directory LDAP None Yes 5.0 Network Low None None None Parti al+ 9.0.4.3, 10.1.2.3, 10.1.4.2
CVE-2008-2612 Hyperion BI Plus HTTP None Yes 4.3 Network Medium None None Partial None 8. 3.2.4, 8.5.0.3, 9.2.0.3, 9.2.1.0, 9.3.1.0 See Note 1
CVE-2008-2614 Oracle HTTP Server HTTP None Yes 4.3 Network Medium None None Partial None 9.0.4.3, 10.1.2.3, 10.1.3.3
CVE-2008-2583 Oracle Portal HTTP OracleAS Discussion Forum Portlet Yes 4.3 Network Medium Non e None Partial None None - See Note Below See Note 2
CVE-2008-2593 Oracle Portal HTTP None Yes 4.3 Network Medium None None Partial None 10.1. 2.3, 10.1.4.2
|
|
Go to the Top of This SecurityTracker Archive Page
|