Showing posts with label Oracle. Show all posts
Showing posts with label Oracle. Show all posts

Saturday, February 23, 2013

HTTP Response Splitting in Oracle EM (policyViewSettings) (CVE-2013-0354)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

TeamSHATTER Security Advisory

HTTP Response Splitting in Oracle Enterprise Manager (policyViewSettings)

February 20, 2013

Risk Level:
Medium

Affected versions:
Oracle Enterprise Manager Database Control 11.1.0.7, 11.2.0.2, 11.2.0.3

Remote exploitable:
Yes

Credits:
This vulnerability was discovered and researched by Esteban Martinez Fayo of
Application Security Inc.

Details:
HTTP Response Splitting is a web application vulnerability where input
parameters are unsafely used in response headers allowing an attacker to make
the server print one (or more) new line sequences in the header section which
allows to set arbitrary headers, take control of the body, or break the
response into two or more separate responses.  This can be used to perform
cross-site scripting, cross-user defacement and web cache poisoning, among
other attacks. The 'pagename' parameter of web page
/em/console/ecm/policy/policyViewSettings is vulnerable to this kind of
attacks.

Impact:
An attacker that convinces a valid Oracle Enterprise Manager user to click or
open a malicious link can take over the user's session.

Vendor Status:
Vendor was contacted and a patch was released.

Workaround:
There is no workaround for this vulnerability.

Fix:
Apply January 2013 CPU.

CVE:
CVE-2013-0354

Links:
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html


https://www.teamshatter.com/?p=4138



Timeline:
Vendor Notification - 6/25/2012
Vendor Response - 6/29/2012
Fix - 1/15/2013
Public Disclosure - 2/20/2013



- --
_____________________________________________
Copyright (c) 2013 Application Security, Inc.
http://www.appsecinc.com



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iEYEARECAAYFAlEmbcQACgkQRx91imnNIgGIXgCghhi6V4QeGQd906/jQwUoCBFL
EM4AoKvhlJs8KHaJfLQLBdhMWgnzx5vD
=xePM
-----END PGP SIGNATURE-----








Courtesy: securityfocus.com

Oracle Database GeoRaster API overflow (CVE-2012-3220)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

TeamSHATTER Security Advisory

Oracle Database GeoRaster API overflow

February 20, 2013

Risk Level:
High

Affected versions:
Oracle Database 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, 11.2.0.3

Remote exploitable:
Yes

Credits:
This vulnerability was discovered and researched by Martin Rakhmanov of
Application Security Inc.

Details:
GeoRaster is a feature of Oracle Spatial that lets you store, index, query,
analyze, and deliver GeoRaster data. One of the GeoRaster APIs is prone to
stack-based overflow.

Impact:
An attacker that can connect to database with spatial support can execute
arbitrary code in the server's process context.

Vendor Status:
Vendor was contacted and a patch was released.

Workaround:
Do not install spatial support in the database.

Fix:
Apply January 2013 CPU.

CVE:
CVE-2012-3220

Links:
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html


https://www.teamshatter.com/?p=4134
 


Timeline:
Vendor Notification - 5/3/2012
Vendor Response - 5/4/2012
Fix - 1/15/2013
Public Disclosure - 2/20/2013
- --
_____________________________________________
Copyright (c) 2013 Application Security, Inc.
http://www.appsecinc.com


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iEYEARECAAYFAlEmbNsACgkQRx91imnNIgGm0wCgoCDtw7yex8egWX0in3tTYGHm
R60Anjf9fKfxgr6y4E28pn3Z+xLWNoJV
=9NkT
-----END PGP SIGNATURE-----









Courtesy: securityfocus.com

Oracle EM Cross Site Scripting in XDBResource cancelURL parameter (CVE-2013-0352)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

TeamSHATTER Security Advisory

Oracle Enterprise Manager Cross Site Scripting in XDBResource cancelURL
parameter

February 20, 2013

Risk Level:
High

Affected versions:
Oracle Enterprise Manager Database Control 10.2.0.3, 10.2.0.4; 10.2.0.5,
11.1.0.7, 11.2.0.2, 11.2.0.3

Remote exploitable:
Yes

Credits:
This vulnerability was discovered and researched by Qinglin Jiang of
Application Security Inc.

Details:
Oracle Enterprise Manager Database Control XML Database Resources page is
vulnerable to a Cross-Site scripting vulnerability. An attacker may inject
malicious code into the web application and trick a legitimate user to execute
it by various methods. The malicious code generally appears in the form of a
script and will be executed in the context of the legitimate user. If a
legitimate user is in a trusted domain or has already been authenticated, the
malicous user may be able to steal session cookies to impersonate a legitimate
user and perform some illegal operations on the web application.

Impact:
Attackers might steal legitimate user's session cookies to impersonate a
legitimate user and perform illegal operations.

Vendor Status:
Vendor was contacted and a patch was released.

Workaround:
There is no workaround for this vulnerability.

Fix:
Apply January 2013 CPU.

CVE:
CVE-2013-0352

Links:
http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html


https://www.teamshatter.com/?p=4125
 


Timeline:
Vendor Notification - 6/25/2012
Vendor Response - 6/29/2012
Fix - 1/15/2013
Public Disclosure - 2/20/2013
- --
_____________________________________________
Copyright (c) 2013 Application Security, Inc.
http://www.appsecinc.com


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iEYEARECAAYFAlEmbNsACgkQRx91imnNIgEXXwCfXMTXf0nmulBLrzLiW7PJ5oDF
8CgAoK1NSJ0yR1HAaRm/P8B53i3sU/Om
=TB1N
-----END PGP SIGNATURE-----








Courtesy: securityfocus.com

Friday, February 22, 2013

SQL Injection in Oracle Alter FBA Table (CVE-2012-1751)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

TeamSHATTER Security Advisory

SQL Injection in Oracle Alter FBA Table

February 20, 2013

Risk Level:
High

Affected versions:
Oracle Database Enterprise Edition 11.1, 11.2

Remote exploitable:
Yes

Credits:
This vulnerability was discovered and researched by Martin Rakhmanov of
Application Security Inc.

Details:
Renaming a table having flashback archive using specially crafted table name
triggers internal SQL injection. This allows users to execute code with
elevated privileges.

Impact:
An attacker having control over a flashback-enabled table can get SYSDBA
privileges.

Vendor Status:
Vendor was contacted and a patch was released.

Workaround:
Do not grant flashback archive privilege to untrusted users. Limit access to
flashback-enabled tables to trusted users only.

Fix:
Apply Oracle Critical Patch Update October 2012 available at Oracle Support.

CVE:
CVE-2012-1751

Links:
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html


https://www.teamshatter.com/?p=4115



Timeline:
Vendor Notification - 1/23/2012
Vendor Response - 1/26/2012
Fix - 16/10/2012
Public Disclosure - 2/20/2013



- --
_____________________________________________
Copyright (c) 2013 Application Security, Inc.
http://www.appsecinc.com



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iEYEARECAAYFAlEmJi0ACgkQRx91imnNIgGSSgCeNs5tl388LdVtPjT1DYu8NcNr
j+YAniPtv6/eaFORuczvrLuIphivSTRL
=MSFT
-----END PGP SIGNATURE-----







Courtesy: securityfocus.com