CVE-2006-5332: SQL Injection
Unspecified vulnerability in xdb.dbmsxdbz in the XMLDB component for Oracle Database 9.2.0.6 and 10.1.0.4 has unknown impact and remote authenticated attack vectors, aka Vuln# DB01. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB01 is for PL/SQL injection in the ENABLEHIERARCHYINTERNAL procedure.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5332?
The severity of CVE-2006-5332 is considered high due to its potential for PL/SQL injection attacks.
How do I fix CVE-2006-5332?
To fix CVE-2006-5332, upgrade your Oracle Database to a version that addresses this vulnerability, preferably the latest updates.
Which versions of Oracle Database are affected by CVE-2006-5332?
CVE-2006-5332 affects Oracle Database versions 9.2.0.6 and 10.1.0.4.
What type of attack vectors are associated with CVE-2006-5332?
CVE-2006-5332 has remote authenticated attack vectors that exploit an unspecified vulnerability in the XMLDB component.
What impact does CVE-2006-5332 have on Oracle Database?
The impact of CVE-2006-5332 is unknown but can potentially allow attackers to perform unauthorized actions through PL/SQL injection.