Summary
This host is installed with Oracle Database Server and is prone to multiple information disclosure vulnerabilities.
Impact
Successful exploitation will allow attackers to obtain potentially sensitive information and manipulate certain data.
Impact Level: Application
Solution
Apply patches from below links,
http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html#AppendixDB http://www.oracle.com/technetwork/topics/security/cpuoct2013verbose-1899842.html#DB
*****
NOTE: Ignore this warning if above mentioned patch is installed.
*****
Insight
Multiple flaws exist in Core RDBMS component and XML Parser component, no further information available at this moment.
Affected
Oracle Database Server version 11.1.0.7, 11.2.0.2, 11.2.0.3, and 12.1.0.1 are affected
Detection
Get the installed version with the help of tnslsnr service and check it is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2013-3826, CVE-2013-5771 -
CVSS Base Score: 6.4
AV:N/AC:L/Au:N/C:P/I:N/A:P
Related Vulnerabilities
- IBM DB2 Client Interfaces component Unspecified Vulnerabilities (Linux)
- Oracle Database Server Authentication Protocol Security Bypass Vulnerability
- MySQL Unspecified vulnerabilities-05 July-2013 (Windows)
- Oracle MySQL Multiple Unspecified vulnerabilities - 02 Jan14 (Windows)
- MariaDB 'COM_CHANGE_USER' Command Insecure Salt Generation Security Bypass Vulnerability