Oracle 10g R1 pitrig_truncate PLSQL Injection (get users hash)
Publish Date: 21 de февраля de 2011
Severity: : Medium
CVE Identifier: CVE-2008-0344,CVE-2008-0348,CVE-2008-0342,CVE-2008-0339,CVE-2008-0340,CVE-2008-0347,CVE-2008-0343,CVE-2008-0345,CVE-2008-0349,CVE-2008-0341,CVE-2008-0346
Advisory Date: 21 de февраля de 2011
DESCRIPTION
There exists an SQL injection vulnerability in Oracle Database Server product. The vulnerability exists due to insufficient validation of arguments supplied to procedures PITRIG_TRUNCATE and PITRIG_DROP in XDB.XDB_PITRIG_PKG package. A remote attacker with valid user credentials may leverage this vulnerability to inject and execute arbitrary SQL code within the security context of the database system administrator.
INFORMATION EXPOSURE
Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1001374
Trend Micro Deep Security DPI Rule Name: 1001374 - Oracle Database Server SQL Injection In PITRIG_TRUNCATE Of XDB_PITRIG_PKG Package
AFFECTED SOFTWARE AND VERSION:
- Oracle