CVE-2006-3698: SQL Injection
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB01 is related to multiple SQL injection vulnerabilities in SYS.DBMSCDCIMPDP using the (a) IMPORTCHANGESET, (b) IMPORTCHANGETABLE, (c) IMPORTCHANGECOLUMN, (d) IMPORTSUBSCRIBER, (e) IMPORTSUBSCRIBEDTABLE, (f) IMPORTSUBSCRIBEDCOLUMN, (g) VALIDATEIMPORT, (h) VALIDATECHANGESET, (i) VALIDATECHANGETABLE, and (j) VALIDATESUBSCRIPTION procedures, and that DB03 is for SQL injection in the MAIN procedure for SYS.KUPW$WORKER.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3698?
The severity of CVE-2006-3698 is currently unknown due to unspecified vulnerabilities.
What components are affected by CVE-2006-3698?
CVE-2006-3698 affects the Change Data Capture (CDC) component and the Data Pump Metadata API in Oracle Database 10.1.0.5.
How can I mitigate the risks associated with CVE-2006-3698?
To mitigate risks associated with CVE-2006-3698, consider applying security patches provided by Oracle for the affected version.
Are there any known exploits for CVE-2006-3698?
As of now, there are no known exploits for CVE-2006-3698 in the wild.
Which versions of Oracle Database are impacted by CVE-2006-3698?
CVE-2006-3698 impacts Oracle Database version 10.1.0.5.