First published: Wed Jan 19 2011(Updated: )
Unspecified vulnerability in the Real User Experience Insight component in Oracle Enterprise Manager Grid Control 6.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Processing. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this is SQL injection in rsynclogdird involving improper escaping of UTF-8 characters while processing log files.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Enterprise Manager Grid Control 10g | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3594 has a severity rating that could allow remote attackers to impact the confidentiality and integrity of the system.
To resolve CVE-2010-3594, apply the latest security patches provided by Oracle for Oracle Enterprise Manager Grid Control 6.0.
CVE-2010-3594 affects users of Oracle Enterprise Manager Grid Control version 6.0.
Yes, CVE-2010-3594 can be exploited by remote attackers due to its nature of affecting the Real User Experience Insight component.
The impacts of CVE-2010-3594 include potential breaches of confidentiality and integrity in the affected Oracle software.