CVE-2005-1197: SQL Injection
SQL injection vulnerability in the SYS.DBMSCDCIPUBLISH.CREATESCNCHANGESET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGESETNAME parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1197?
CVE-2005-1197 is classified as a medium severity vulnerability due to its potential to allow remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2005-1197?
To fix CVE-2005-1197, it is recommended to apply the appropriate patches from Oracle or upgrade to a secured version of the Oracle Database.
Which versions of Oracle Database are affected by CVE-2005-1197?
CVE-2005-1197 affects Oracle Database Server versions 10.1.0.2, 10.1.0.3, 10.1.0.3.1, and 10.1.0.4.
What causes the vulnerability in CVE-2005-1197?
The vulnerability in CVE-2005-1197 is caused by improper validation of the CHANGE_SET_NAME parameter in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure.
Can CVE-2005-1197 be exploited remotely?
Yes, CVE-2005-1197 can be exploited remotely by attackers who can send specially crafted SQL commands.