First published: Sat Dec 31 2005(Updated: )
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2) SYS.DBMS_CDC_ISUBSCRIBE packages, a different vector than CVE-2005-1197.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database 10g | =enterprise_9.0.4.0 | |
Oracle Database 10g | =enterprise_9.0.4_.0 | |
Oracle Database 10g | =enterprise_10.1.0.2 | |
Oracle Database 10g | =enterprise_10.1.0.3 | |
Oracle Database 10g | =enterprise_10.1.0.3.1 | |
Oracle Database 10g | =enterprise_10.1.0.4 | |
Oracle Database 10g | =enterprise_10.2.3 | |
Oracle Database 10g | =personal_9.0.4.0 | |
Oracle Database 10g | =personal_9.0.4_.0 | |
Oracle Database 10g | =personal_10.1.0.2 | |
Oracle Database 10g | =personal_10.1.0.3 | |
Oracle Database 10g | =personal_10.1.0.3.1 | |
Oracle Database 10g | =personal_10.1.0.4 | |
Oracle Database 10g | =personal_10.1_.0.2 | |
Oracle Database 10g | =personal_10.2.3 | |
Oracle Database 10g | =personal_10.10.3.1 | |
Oracle Database 10g | =standard_9.0.4.0 | |
Oracle Database 10g | =standard_9.0.4_.0 | |
Oracle Database 10g | =standard_10.1.0.2 | |
Oracle Database 10g | =standard_10.1.0.3 | |
Oracle Database 10g | =standard_10.1.0.3.1 | |
Oracle Database 10g | =standard_10.1.0.4 | |
Oracle Database 10g | =standard_10.1.0.4.2 | |
Oracle Database 10g | =standard_10.1.0.5 | |
Oracle Database 10g | =standard_10.1_.0.2 | |
Oracle Database 10g | =standard_10.2.0.1 | |
Oracle Database 10g | =standard_10.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4832 has a high severity level due to its potential to allow remote authenticated users to execute arbitrary SQL commands with elevated privileges.
To mitigate CVE-2005-4832, apply the latest patches provided by Oracle for the affected versions of the Oracle Database Server.
CVE-2005-4832 affects several versions of Oracle Database 10g, including specific enterprise, personal, and standard editions.
Exploiting CVE-2005-4832 can lead to unauthorized access to sensitive data and the ability to manipulate database content.
Organizations using vulnerable versions of Oracle Database 10g configured with insufficient security measures are at risk of CVE-2005-4832.