Description
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 have unknown impact and remote authenticated attack vectors related to (1) SDO_UTIL in the Oracle Spatial component, aka DB05; or (2) fine grained auditing in the Audit component, aka DB14. NOTE: the previous information was obtained from the Oracle CPU. Oracle has not commented on reliable researcher claims that DB05 is SQL injection.
Remediation
References
Related Vulnerabilities
WordPress Plugin Captchinoo, Google recaptcha for admin login page Security Bypass (2.3)
Plone CMS CVE-2011-3587 Vulnerability (CVE-2011-3587)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2156)
Oracle Database Server CVE-2011-2239 Vulnerability (CVE-2011-2239)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-1488)