CVE-2006-5340: SQL Injection
Multiple unspecified vulnerabilities in Oracle Spatial component in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 have unknown impact and remote authenticated attack vectors related to (1) mdsys.sdolrs, aka Vuln# DB13, and (2) Vuln# DB17. NOTE: as of 20061023, Oracle has not disputed reports from reliable third parties that DB13 is related to bypassing input validation for SQL injection related to converttolrslayer and dbmsassert, and DB17 is related to SQL injection in the trigger in the SDODROPUSER package.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5340?
The severity of CVE-2006-5340 has not been clearly defined, but it involves multiple unspecified vulnerabilities in Oracle Database.
Which Oracle Database versions are affected by CVE-2006-5340?
CVE-2006-5340 affects Oracle Database versions 8.1.7.4, 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2.
What are the attack vectors for CVE-2006-5340?
CVE-2006-5340 involves remote authenticated attack vectors related to the mdsys.sdo_lrs function.
How do I mitigate the risks associated with CVE-2006-5340?
Mitigation for CVE-2006-5340 involves updating to a patched version of the Oracle Database as advised by Oracle.
Is there a known impact of CVE-2006-5340?
The exact impact of CVE-2006-5340 remains unknown, but it could potentially allow for exploitation via the affected components.