vendor:
Oracle Database Server
by:
Andrea 'bunker' Purificato
9
CVSS
CRITICAL
Multiple vulnerabilities
385
CWE
Product Name: Oracle Database Server
Affected Version From: All supported releases
Affected Version To: Not specified
Patch Exists: YES
Related CWE: CVE-2007-3855
CPE: cpe:2.3:a:oracle:oracle_database_server:*:*:*:*:*:*:*:*
Platforms Tested:
2007
Oracle Multiple Vulnerabilities
The Oracle Critical Patch Update advisory for July 2007 addresses multiple vulnerabilities that affect all security properties of the Oracle products. These vulnerabilities pose both local and remote threats, with some requiring various levels of authorization to exploit. The most severe vulnerabilities could lead to complete compromise of affected computers. One specific exploit mentioned is the 'bunkerview.sql' evil view exploit (CVE-2007-3855), which allows unauthorized password updates.
Mitigation:
Apply the Critical Patch Update for July 2007 from Oracle to address the vulnerabilities. Additionally, ensure that unsupported releases are upgraded to supported versions.