CVE-2006-0586
Published Feb 8, 2006
Last updated a year ago
Overview
- Description
- Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DELETE_JOB, (10) DELETE_MASTER_TABLE, (11) DETACH_JOB, (12) GET_JOB_INFO, (13) GET_JOB_QUEUES, (14) GET_SOLE_JOBNAME, (15) MASTER_TBL_LOCK, and (16) VALID_HANDLE functions in the SYS.KUPV$FT_INT package. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that these issues has been addressed by Oracle. It is unclear which, if any, Oracle Vuln# identifiers apply to these issues.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- CWE-89
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:oracle:application_server:10.1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1C1B82E1-D1AD-46F2-8B95-117F38563FC6" }, { "criteria": "cpe:2.3:a:oracle:application_server:10.1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6FC5FDD9-F24C-4DA2-9CE3-96522DB4A10E" }, { "criteria": "cpe:2.3:a:oracle:application_server:10.1.0.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DDECF110-F375-4A3C-8BA9-1CF69B6EF027" }, { "criteria": "cpe:2.3:a:oracle:application_server:10.1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "77F36775-7D44-405E-8DE3-EBD71C9EE421" }, { "criteria": "cpe:2.3:a:oracle:application_server:10.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D94B7D50-4527-4C14-8A50-D4C0566F36BA" }, { "criteria": "cpe:2.3:a:oracle:application_server:10.1.2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FB8F5AAE-0365-4E01-AB04-CDC6D58B00B6" }, { "criteria": "cpe:2.3:a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0B4BAA9-D045-4D2B-8220-47F47ED936DF" }, { "criteria": "cpe:2.3:a:oracle:application_server:10.1.2.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE6C4D36-D9D1-4143-94AA-D8E08F23D2E3" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C033CC3-1840-49A1-AB6E-3EC8CE1F0BEE" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD4E604B-6C0D-474F-A3A9-B07EF0A7D2E2" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8667E51F-86A9-4181-8FCC-BECC6F50913B" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:enterprise_10.1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA52C2C2-64C3-40BA-86A1-C4A14BEB8CCE" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2C84E349-48A8-4800-A300-AACEC8659656" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "323353FE-7ECD-4668-BDB1-3E5CA8F3F9A9" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:personal_10.1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B33627F4-3E7D-4181-8171-2B65F8C60E7C" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:personal_10.10.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86D1E996-3AD3-4B17-B959-6790BC735F13" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8975840-9843-4034-BBED-B31A9BA16DF0" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0A39665-BB49-4135-9850-8CF9E69546FA" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2764001-8B54-47AD-A265-0C0B0F691A15" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "41B5ED54-BAF4-41B3-8B09-F9795AB7A18A" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D2EA2727-2F53-470F-AF58-1B33B7A5B7EF" }, { "criteria": "cpe:2.3:a:oracle:oracle10g:standard_10.1.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EAD20B6-258F-4093-BEE0-99F11D61A61F" } ], "operator": "OR" } ] } ]