Oracle Database Server SQL Injection In SDO_IDX Package
2015年7月21日
危険度: 緊急
CVE識別番号: CVE-2008-1817
情報公開日: 7 21, 2015
概要
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 have unknown impact and remote attack vectors related to (1) SDO_IDX in the Spatial component, aka DB07; and (2) Core RDBMS, aka DB10. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB07 is SQL injection.
トレンドマイクロの対策
Apply associated Trend Micro DPI Rules.
対応方法
Trend Micro Deep Security DPI Rule Number: 1002430
Trend Micro Deep Security DPI Rule Name: 1002430 - Oracle Database Server SQL Injection In SDO_IDX Package
影響を受けるソフトウェア
- Oracle Database 10g 10.1.0.5
- Oracle Database 10g 10.2.0.3
- racle Database 11g 11.1.0.6
- Oracle Database 9i 9.0.1.5 FIPS+
- Oracle Database 9i 9.2.0.8DV