First published: Mon May 22 2006(Updated: )
Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a reference to a malicious package in the TYPE_NAME argument in the (1) GET_DOMAIN_INDEX_TABLES or (2) GET_V2_DOMAIN_INDEX_TABLES function in the DBMS_EXPORT_EXTENSION package.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =release_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2505 is considered a critical vulnerability due to its potential to allow local users to execute arbitrary SQL queries.
To remediate CVE-2006-2505, ensure that only trusted users have access to the Oracle Database Server to limit exposure.
CVE-2006-2505 specifically affects Oracle Database Server 10g Release 2.
No, CVE-2006-2505 requires local access to exploit the vulnerability.
The implications of CVE-2006-2505 include unauthorized access to sensitive data through arbitrary SQL query execution.