CVE-2006-1884: Critical severity Oracle Database Server vulnerability
Published Apr 20, 2006
·Updated
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
Affected Software
46 affected components
Oracle Database Server=10.2.0.2
Oracle Developer Suite=6i
Oracle Application Server=10.1.2.0.2
Oracle Enterprise Manager Grid Control=10.1.0.4
Oracle E-Business Suite=11.5.10.1
Oracle Database Server=10.2.0.4.2
Oracle Database Server=8.1.7.4
Oracle Peoplesoft Enterprise Tools=8.46-ga
Oracle Database Server=10.2.0.4
Oracle Application Server=10.1.2.1.0
Oracle Database Server=9.0.1.5
Oracle Collaboration Suite 10g Release 1=10.1.2.1
Oracle E-Business Suite=11.0
JDEdwards Enterpriseone Tools=8.95.j1
Oracle Database Server=9.2.0.7
Oracle Application Server=10.1.2.0.0
Oracle Enterprise Manager Grid Control=10.1.0.3
Oracle Database Server=8.0.6.3
Oracle Application Server=9.0.4.1
Oracle Workflow=11.5.9.5
Oracle E-Business Suite=11.5.10.2
Oracle Enterprise Manager Grid Control=10.2.0.1
Oracle Peoplesoft Enterprise Tools=8.47.04
Oracle E-Business Suite=11.5.1
Oracle Pharmaceutical=4.5.1
Oracle Application Server=10.1.2.0.1
Oracle Collaboration Suite 10g Release 1=10.1.1
Oracle Peoplesoft Enterprise Tools=8.47-ga
Oracle Database Server=9.2.0.6
Oracle Application Server=10.1.3.0.0
Oracle Collaboration Suite=9.0.4.2
Oracle Database Server=10.2.0.5
Oracle E-Business Suite=11.5.10
Oracle Pharmaceutical=4.5.2
Oracle Workflow=11.5.1
Oracle Collaboration Suite 10g Release 1=10.1.2.0
Oracle Application Server=1.0.2.2
Oracle Database Server=9.0.1.4
Oracle Peoplesoft Enterprise Tools=8.46.12
Oracle Pharmaceutical=4.5.0
Oracle Developer Suite=9.0.4.2
Oracle Application Server=9.0.4.2
Oracle Database Server=10.2.0.1
JDEdwards Enterpriseone Tools=8.95
Oneworld Oneworld Tools=8.95.j1
Oneworld Oneworld Tools=8.95
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 20, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-1884?
The severity of CVE-2006-1884 is currently unknown due to unspecified impact and attack vectors.
2
What systems are affected by CVE-2006-1884?
CVE-2006-1884 affects various versions of Oracle E-Business Suite, Oracle Application Server, Oracle Database, and JD Edwards EnterpriseOne Tools.
3
How can I mitigate CVE-2006-1884?
Mitigation for CVE-2006-1884 should involve applying security patches from Oracle for the affected software.
4
Is there a known exploit for CVE-2006-1884?
As of now, there are no known exploits publicly available for CVE-2006-1884.
5
Should I be concerned about CVE-2006-1884 in my environment?
Yes, you should assess the risk of CVE-2006-1884 in your environment, particularly if you are using any affected Oracle products.