CVE-2006-5338: SQL Injection
Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5 has unknown impact and remote authenticated attack vectors related to sys.dbmssqltune, aka Vuln# DB10. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB10 is for SQL injection in DROPSQLSET, DELETESQLSET, SELECTSQLSET, and ISETTUNINGPARAMETER. NOTE: some of these vectors might be in DBMSSQLTUNEINTERNAL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5338?
CVE-2006-5338 is considered to have an unspecified severity level due to its unknown impact.
How do I fix CVE-2006-5338?
To address CVE-2006-5338, apply the latest security patches provided by Oracle for affected versions.
Which software versions are affected by CVE-2006-5338?
CVE-2006-5338 affects Oracle Database versions 10.1.0.5 and 10.2.0.0.
What kind of attack vectors are associated with CVE-2006-5338?
CVE-2006-5338 is associated with remote authenticated attack vectors related to the sys.dbms_sqltune package.
Is CVE-2006-5338 related to SQL injection vulnerabilities?
Yes, CVE-2006-5338 has been reported to be related to SQL injection vulnerabilities.