First published: Fri Jul 21 2006(Updated: )
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =10.1.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The exact severity of CVE-2006-3705 is unspecified, but it involves multiple vulnerabilities with potentially significant impact.
To address CVE-2006-3705, ensure your Oracle Database is updated to a version that mitigates the vulnerabilities.
CVE-2006-3705 includes vulnerabilities related to local SQL injection, though the exact attack vectors remain unspecified.
CVE-2006-3705 affects version 10.1.0.5 of Oracle Database.
There are currently no publicly available exploits specifically associated with CVE-2006-3705, but vulnerabilities may be leveraged in specific contexts.