int(2123)

Boletines de Vulnerabilidades


Oracle publica parche acumulativo

Clasificación de la vulnerabilidad

Propiedad Valor
Nivel de Confianza Oficial
Impacto Integridad
Dificultad Principiante
Requerimientos del atacante Acceso remoto sin cuenta a un servicio estandar

Información sobre el sistema

Propiedad Valor
Fabricante afectado Comercial Software
Software afectado Oracle Database 10g Release 2, version 10.2.0.1
Oracle Database 10g Release 1, versions 10.1.0.3, 10.1.0.4, 10.1.0.5
Oracle9i Database Release 2, versions 9.2.0.6, 9.2.0.7
Oracle8i Database Release 3, version 8.1.7.4
Oracle Enterprise Manager 10g Grid Control, versions 10.1.0.3, 10.1.0.4
Oracle Application Server 10g Release 2, versions 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1.0
Oracle Application Server 10g Release 1 (9.0.4), versions 9.0.4.1, 9.0.4.2
Oracle Collaboration Suite 10g Release 1, versions 10.1.1, 10.1.2
Oracle9i Collaboration Suite Release 2, version 9.0.4.2
Oracle E-Business Suite Release 11i, versions 11.5.1 through 11.5.10 CU2
Oracle E-Business Suite Release 11.0
PeopleSoft Enterprise Portal, versions 8.4, 8.8, 8.9
JD Edwards EnterpriseOne Tools, OneWorld Tools, versions 8.95.F1, SP23_L1
Oracle Database 10g Release 1, version 10.1.0.4.2
Oracle Developer Suite, versions 6i, 9.0.2.1, 9.0.4.1, 9.0.4.2, 10.1.2.0
Oracle Workflow, versions 11.5.1 through 11.5.9.5
Oracle9i Database Release 1, versions 9.0.1.4, 9.0.1.5, 9.0.1.5 FIPS
Oracle8 Database Release 8.0.6, version 8.0.6.3
Oracle9i Application Server Release 1, version 1.0.2.2

Descripción

Se ha publicado el parche acumulativo de Enero para los siguientes productos de Oracle: Oracle Database Server, Enterprise Manager, Oracle Application Server, Oracle Collaboration Suite, Oracle E-Business Suite,
PeopleSoft Enterprise Portal, JD Edwards EnterpriseOne Tools.

Este parche soluciona múltiples vulnerabilidades que pueden comprometer la integridad, confidencialidad y disponibilidad de dichos productos asi como la información manejada por ellos.

Solución



Actualización de software

Oracle
Oracle Database Server
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=343384.1
Oracle Application Server
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=343385.1
Oracle Collaboration Suite
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=343387.1
Oracle E-Business Suite and Applications
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=343389.1
Oracle Enterprise Manager
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=343390.1
Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne
http://www.peoplesoft.com/corp/en/support/security_index.jsp

Identificadores estándar

Propiedad Valor
CVE CAN-2005-2371
CAN-2005-2378
CVE-2006-0256
CVE-2006-0257
CVE-2006-0258
CVE-2006-0259
CVE-2006-0260
CVE-2006-0261
CVE-2006-0262
CVE-2006-0263
CVE-2006-0264
CVE-2006-0265
CVE-2006-0266
CVE-2006-0267
CVE-2006-0268
CVE-2006-0269
BID

Recursos adicionales

Oracle Critical Patch Update - January 2005
http://www.oracle.com/technology/deploy/security/pdf/cpujan2006.html

red-database-security - Security Advisory (17/01/2006)
http://www.red-database-security.com/advisory/oracle_sql_injection_dbms_metadata_util.html

red-database-security - Security Advisory (17/01/2006)
http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft.html

red-database-security - Security Advisory (17/01/2006)
http://www.red-database-security.com/advisory/oracle_sql_injection_kupv$ft_int.html

red-database-security - Security Advisory (17/01/2006)
http://www.red-database-security.com/advisory/oracle_tde_wallet_password.html

red-database-security - Security Advisory (17/01/2006)
http://www.red-database-security.com/advisory/oracle_tde_unencrypted_sga.html

red-database-security - Security Advisory (25/08/2005)
http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html

red-database-security - Security Advisory (25/08/2005)
http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html

red-database-security - Security Advisory (25/08/2005)
http://www.red-database-security.com/advisory/oracle_reports_overwrite_any_file.html

HP Security Advisory HPSBMA02094
http://www4.itrc.hp.com/service/cki/docDisplay.do?docId=c00593668

Histórico de versiones

Versión Comentario Fecha
1.0 Aviso emitido 2006-01-18
1.1 Aviso emitido por HP (HPSBMA02094) 2006-01-24
1.2 CVE añadido. Exploit público disponible. 2006-02-15

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT